CVE-2017-18175: Progress Sitefinity
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
Affected products
- Progress Sitefinity: version 9.1 only
Published 2018-02-12. Last modified 2026-06-17.