Arbitrary File Upload Vulnerability in Progress Sitefinity CMS
CVE-2018-17055
7.5HIGH
Summary
Progress Sitefinity CMS versions 4.0 through 11.0 are susceptible to an arbitrary file upload vulnerability, which can allow malicious users to upload harmful files via the image upload feature. This vulnerability can potentially lead to unauthorized code execution, making it crucial for organizations using these versions to immediately implement security measures as outlined in the vendor's security advisories.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved