VYPR
Medium severity6.1NVD Advisory· Published Feb 12, 2018· Updated Jun 17, 2026

CVE-2017-18178

CVE-2017-18178

Description

Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.

Affected products

2
  • cpe:2.3:a:progress:sitefinity:9.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:progress:sitefinity:9.1:*:*:*:*:*:*:*
    • (no CPE)range: <10.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.