CVE-2024-11626
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web del backend de CMS (sección administrativa) (XSS o 'Cross-site Scripting') en Progress Sitefinity. Este problema afecta a Sitefinity: desde la versión 4.0 hasta la 14.4.8142, desde la versión 15.0.8200 hasta la 15.0.8229, desde la versión 15.1.8300 hasta la 15.1.8327, desde la versión 15.2.8400 hasta la 15.2.8421.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-11-22 CVE Reserved
- 2025-01-07 CVE Published
- 2025-01-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
- CAPEC-63: Cross-Site Scripting (XSS)
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Software Corporation Search vendor "Progress Software Corporation" | Sitefinity Search vendor "Progress Software Corporation" for product "Sitefinity" | >= 4.0.0 <= 14.4.8142 Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 4.0.0 <= 14.4.8142" | en |
Affected
| ||||||
Progress Software Corporation Search vendor "Progress Software Corporation" | Sitefinity Search vendor "Progress Software Corporation" for product "Sitefinity" | >= 15.0.8200 <= 15.0.8229 Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 15.0.8200 <= 15.0.8229" | en |
Affected
| ||||||
Progress Software Corporation Search vendor "Progress Software Corporation" | Sitefinity Search vendor "Progress Software Corporation" for product "Sitefinity" | >= 15.1.8300 <= 15.1.8327 Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 15.1.8300 <= 15.1.8327" | en |
Affected
| ||||||
Progress Software Corporation Search vendor "Progress Software Corporation" | Sitefinity Search vendor "Progress Software Corporation" for product "Sitefinity" | >= 15.2.8400 <= 15.2.8421 Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 15.2.8400 <= 15.2.8421" | en |
Affected
|