CVE-2024-11626
CVSS 3.1 Score 8.4 of 10 (high)
Details
Summary
CVE-2024-11626 is a Cross-site Scripting (XSS) vulnerability affecting various versions of Progress Sitefinity. The flaw, which exists in the CMS backend's administrative section, allows attackers to inject malicious scripts into web pages. Affected versions include Sitefinity 4.0 through 14.4.8142, 15.0.8200 through 15.0.8229, 15.1.8300 through 15.1.8327, and 15.2.8400 through 15.2.8421. Successful exploitation of this vulnerability could lead to unauthorized access to user sessions or data theft. Users of these affected versions are advised to upgrade to the latest patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Progress SiteFinity
Affected Vendors
- Progress Publishers