nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18639 CVE-2017-18639
MEDIUM
Sitefinity CMS 9.2 - Cross-Site Scripting
Record summary
CVE-2017-18639 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, /Content/List Parameter : List Title, /Content/Documents/LibraryDocuments/incident-request-attachments Parameter : Document Title, /Content/Images/LibraryImages/newsimages Parameter : Image Title, /Content/links Parameter : Link Title, /Content/links Parameter : Link Title, or /Content/Videos/LibraryVideos/default-video-library Parameter : Video Title.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSitefinity CMS 9.2 - Cross-Site ScriptingExploitDB exploitby Pralhad ChaskarNot analyzed1 file
References
2exploit-db.com
https://www.exploit-db.com/exploits/42792