Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown

CVE-2019-17392

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
Attacker Value
Unknown

CVE-2017-18639

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, /Content/List Parameter : List Title, /Content/Documents/LibraryDocuments/incident-request-attachments Parameter : Document Title, /Content/Images/LibraryImages/newsimages Parameter : Image Title, /Content/links Parameter : Link Title, /Content/links Parameter : Link Title, or /Content/Videos/LibraryVideos/default-video-library Parameter : Video Title.
Attacker Value
Unknown

CVE-2019-7215

Disclosure Date: June 06, 2019 (last updated November 08, 2023)
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
0
Attacker Value
Unknown

CVE-2018-17054

Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17053.
0
Attacker Value
Unknown

CVE-2018-17053

Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054.
0
Attacker Value
Unknown

CVE-2018-17056

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-17055

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
0
Attacker Value
Unknown

CVE-2017-18178

Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
0
Attacker Value
Unknown

CVE-2017-18175

Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
0
Attacker Value
Unknown

CVE-2017-18176

Disclosure Date: February 12, 2018 (last updated November 26, 2024)
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
0