CVE-2024-11626

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 79

Summary

CVE-2024-11626 is a Cross-site Scripting (XSS) vulnerability affecting various versions of Progress Sitefinity. The flaw, which exists in the CMS backend's administrative section, allows attackers to inject malicious scripts into web pages. Affected versions include Sitefinity 4.0 through 14.4.8142, 15.0.8200 through 15.0.8229, 15.1.8300 through 15.1.8327, and 15.2.8400 through 15.2.8421. Successful exploitation of this vulnerability could lead to unauthorized access to user sessions or data theft. Users of these affected versions are advised to upgrade to the latest patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Progress SiteFinity

Affected Vendors

  • Progress Publishers