CVE-2019-13493

MEDIUM

Sitecore XP 9.0.171002 Authenticated Stored XSS in Media Library

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-13493. PoCs published by Owais Mehtab.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Sitecore CMS 9.0 rev 171002, where the file extension parameter is not properly escaped. An attacker can inject malicious scripts via the media library's extension input field, potentially affecting administrators, users, or editors.

Description

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

Exploits (1)

exploitdb WORKING POC
by Owais Mehtab · textwebappsaspx
https://www.exploit-db.com/exploits/47106

This exploit demonstrates a stored XSS vulnerability in Sitecore CMS 9.0 rev 171002, where the file extension parameter is not properly escaped. An attacker can inject malicious scripts via the media library's extension input field, potentially affecting administrators, users, or editors.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Sitecore CMS 9.0 rev 171002
Auth required
Prerequisites: Valid credentials to access the Sitecore CMS admin panel
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0158
EPSS Percentile 72.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
sitecore/experience_platform 9.0
Published Jul 17, 2019
Tracked Since Feb 18, 2026