CVE-2023-29375: Malicious File Upload
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29375?
CVE-2023-29375 is a vulnerability in Progress Sitefinity versions 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025 that allows for potentially dangerous file upload through the SharePoint connector.
How severe is CVE-2023-29375?
CVE-2023-29375 is rated as critical with a severity score of 9.8.
What software is affected by CVE-2023-29375?
Progress Sitefinity versions 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025 are affected by CVE-2023-29375.
How can I fix CVE-2023-29375?
To fix CVE-2023-29375, upgrade Progress Sitefinity to version 13.3.7647, 14.0.7736, 14.1.7826, 14.2.7930, or 14.3.8025.
Where can I find more information about CVE-2023-29375?
More information about CVE-2023-29375 can be found in the Sitefinity Security Advisory and on the Progress Sitefinity CMS website.