First published: Fri Sep 28 2018(Updated: )
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Sitefinity CMS | >=10.2<=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17056 is a cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0.
CVE-2018-17056 has a severity rating of 6.1 (Medium).
CVE-2018-17056 allows remote attackers to inject arbitrary web script or HTML into Progress Sitefinity CMS.
CVE-2018-17056 is categorized as CWE-79, which is a vulnerability related to cross-site scripting (XSS).
To fix CVE-2018-17056, it is recommended to update to a version of Progress Sitefinity CMS that is not affected by this vulnerability, such as version 11.0 or higher.