Cross-site scripting (XSS) in Identity Server nelle versioni Progress Sitefinity CMS da 10.0 a 11.0 consente agli aggressori remoti di inserire lo script Web arbitrario o HTML tramite vettori relativi a parametri di richiesta di accesso, una vulnerabilità diverso rispetto CVE-2.018-17.053. |
https://knowledgebase.progress.com/articles/Article/Security-Advisory-for-Resolving-Security-vulnerabilities-September-2018 https://insinuator.net/2018/10/vulnerabilities-in-sitefinity-wcms-a-success-story-of-a-responsible-disclosure-process/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17054 |
Vulnerabilità: CVE-2018-17054
