Record summary

CVE-2014-100004 has a selected CVSS score of 4.3; EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to inject arbitrary web script or HTML via the xmlcontrol parameter to the default URI. NOTE: some of these details are obtained from third party information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMSitecore CMS - Cross-Site ScriptingCVSS 6.1

Sitecore CMS contains a cross-site scripting vulnerability via the "special way" of displaying XML Controls directly, which allows for a Cross Site Scripting Attack.

Impact

Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.

Remediation

Update to a patched version of Sitecore CMS or apply vendor security updates.

WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscvecve2014xsssitecorecmsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sitecore:sitecore.net:*:*:*:*:*:*:*:*
Shodan: html:"Sitecore"

Source: ProjectDiscovery

References

7