First published: Mon Jul 08 2024(Updated: )
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Sitefinity | <15.1.8321.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4882 is classified as a high-severity vulnerability due to its ability to redirect users to arbitrary sites.
To fix CVE-2024-4882, users should update Sitefinity to version 15.1.8322.0 or later.
CVE-2024-4882 affects Sitefinity versions up to and including 15.1.8321.0.
CVE-2024-4882 enables open redirect attacks, where users can be redirected to malicious sites.
A temporary workaround for CVE-2024-4882 involves sanitizing and validating redirect URLs before processing.