CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
External Security References
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2017-18176
Severity
MEDIUM
CVSS
5.4
EPSS
0.70%
Java
Original NVD Description
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)