CVE-2014-100004
Sitecore CMS - Cross-Site Scripting
Record summary
CVE-2014-100004 has a selected CVSS score of 4.3; EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to inject arbitrary web script or HTML via the xmlcontrol parameter to the default URI. NOTE: some of these details are obtained from third party information.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSitecore CMS - Cross-Site ScriptingCVSS 6.1
Sitecore CMS contains a cross-site scripting vulnerability via the "special way" of displaying XML Controls directly, which allows for a Cross Site Scripting Attack.
Impact
Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.
Remediation
Update to a patched version of Sitecore CMS or apply vendor security updates.
Source: ProjectDiscovery