CVE-2023-27636

MEDIUM

Progress Sitefinity < 15.0.0 - Authenticated Cross-Site Scripting via Content Form

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-27636. PoCs published by Aldi Saputra Wahyudi.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Sitefinity CMS versions prior to 15.0.0, where an attacker with lower privileges can inject malicious JavaScript payloads via the SF-Editor, which execute when a higher-privileged user views the affected page.

Description

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

Exploits (1)

exploitdb WORKING POC
by Aldi Saputra Wahyudi · textwebappsmultiple
https://www.exploit-db.com/exploits/52035

This exploit demonstrates a stored XSS vulnerability in Sitefinity CMS versions prior to 15.0.0, where an attacker with lower privileges can inject malicious JavaScript payloads via the SF-Editor, which execute when a higher-privileged user views the affected page.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Progress Sitefinity CMS < 15.0.0
Auth required
Prerequisites: Attacker must have access to a feature using SF-Editor (e.g., news creation/editing) · Victim must visit the page containing the injected payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0048
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
progress/sitefinity < 15.0.0
Published Jun 16, 2024
Tracked Since Feb 18, 2026