CVE-2018-17056

MEDIUM

ServiceStack in Progress Sitefinity CMS <11.0 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Scores

CVSS v3 6.1
EPSS 0.0008
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
progress/sitefinity_cms 10.2 - 11.0
Published Sep 28, 2018
Tracked Since Feb 18, 2026