Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown

CVE-2024-11627

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown

CVE-2024-11626

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown

CVE-2024-11625

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown

CVE-2024-4882

Disclosure Date: July 08, 2024 (last updated July 09, 2024)
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
0
Attacker Value
Unknown

CVE-2023-27636

Disclosure Date: June 16, 2024 (last updated August 09, 2024)
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
Attacker Value
Unknown

CVE-2024-1636

Disclosure Date: February 28, 2024 (last updated December 18, 2024)
Potential Cross-Site Scripting (XSS) in the page editing area.
Attacker Value
Unknown

CVE-2024-1632

Disclosure Date: February 28, 2024 (last updated December 18, 2024)
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.
Attacker Value
Unknown

CVE-2023-6784

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
Attacker Value
Unknown

CVE-2023-29376

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.
Attacker Value
Unknown

CVE-2023-29375

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.