CVE-2023-29376
 
Severity Score
5.4
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-04-05 CVE Reserved
- 2023-04-10 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 13.3 < 13.3.7646 Search vendor "Progress" for product "Sitefinity" and version " >= 13.3 < 13.3.7646" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.0 < 14.0.7736 Search vendor "Progress" for product "Sitefinity" and version " >= 14.0 < 14.0.7736" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.1 < 14.1.7826 Search vendor "Progress" for product "Sitefinity" and version " >= 14.1 < 14.1.7826" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.2 < 14.2.7930 Search vendor "Progress" for product "Sitefinity" and version " >= 14.2 < 14.2.7930" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.3 < 14.3.8026 Search vendor "Progress" for product "Sitefinity" and version " >= 14.3 < 14.3.8026" | - |
Affected
|