CVE-2017-18176
12.02.2018, 14:29
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
Vendor | Product | Version |
---|---|---|
progress | sitefinity | 9.1 |
𝑥
= Vulnerable software versions
References