The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www.progress.com/sitefinity-cms | product |
https://community.progress.com/s/article/Open-Redirect-vulnerability-CVE-2024-4882 | vendor advisory |