First published: Tue Jan 07 2025(Updated: )
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Sitefinity CMS | >=4.0>=14.0<=14.4.8142>=15.0.8200<=15.0.8229>=15.1.8300<=15.1.8327>=15.2.8400<=15.2.8421 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11626 is classified as a moderate severity Cross-Site Scripting (XSS) vulnerability affecting Progress Sitefinity.
To fix CVE-2024-11626, upgrade your Progress Sitefinity installation to the latest version that addresses this vulnerability.
CVE-2024-11626 affects Progress Sitefinity versions from 4.0 to 14.4.8142, 15.0.8200 to 15.0.8229, and 15.1.8300 to 15.1.8327.
Yes, CVE-2024-11626 is an XSS vulnerability caused by improper input neutralization in the CMS backend of Progress Sitefinity.
Cross-Site Scripting (XSS) in the context of CVE-2024-11626 allows an attacker to inject malicious scripts into web pages viewed by other users of the Progress Sitefinity platform.