CVE-2023-29376: XSS
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29376?
CVE-2023-29376 is a vulnerability in Progress Sitefinity versions 13.3 to 14.3 that allows privileged users to perform XSS attacks in media libraries.
What is the severity of CVE-2023-29376?
The severity of CVE-2023-29376 is medium, with a CVSS score of 5.4.
Which versions of Progress Sitefinity are affected by CVE-2023-29376?
Progress Sitefinity versions 13.3 to 14.3 are affected by CVE-2023-29376.
How can privileged users exploit CVE-2023-29376?
Privileged users can exploit CVE-2023-29376 by conducting cross-site scripting attacks in Sitefinity media libraries.
Are there any fixes or patches available for CVE-2023-29376?
Yes, fixes or patches for CVE-2023-29376 are available in versions 13.3.7647, 14.0.7736, 14.1.7826, 14.2.7930, and 14.3.8025 of Progress Sitefinity.