packetstormsecurity.com
http://packetstormsecurity.com/files/153613/Sitecore-9.0-Rev-171002-Cross-Site-Scripting.html CVE-2019-13493
MEDIUM
Sitecore 9.0 rev 171002 - Persistent Cross-Site Scripting
Record summary
CVE-2019-13493 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSitecore 9.0 rev 171002 - Persistent Cross-Site ScriptingExploitDB exploitby Owais MehtabNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-13493