First published: Mon Jun 03 2024(Updated: )
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
Credit: Aldi Saputra Wahyudi cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress | <15.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27636 is considered a high severity vulnerability due to its potential for XSS attacks by authenticated users.
To fix CVE-2023-27636, upgrade to Progress Sitefinity version 15.0.0 or later.
CVE-2023-27636 affects all versions of Progress Sitefinity prior to 15.0.0.
CVE-2023-27636 is an XSS (cross-site scripting) vulnerability.
No, CVE-2023-27636 can only be exploited by authenticated users.