Lucene search

K
cvelistMitreCVELIST:CVE-2017-18176
HistoryFeb 12, 2018 - 2:00 p.m.

CVE-2017-18176

2018-02-1214:00:00
mitre
www.cve.org
1
progress sitefinity
xss
file upload
javascript
html
same origin
application code
cve-2017-18176
fixed

EPSS

0.001

Percentile

45.8%

Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application’s own code. This is fixed in 10.1.

EPSS

0.001

Percentile

45.8%

Related for CVELIST:CVE-2017-18176