Record summary

CVE-2019-13493 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.

Description

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSitecore 9.0 rev 171002 - Persistent Cross-Site ScriptingExploitDB exploitby Owais MehtabNot analyzed1 file
ExploitDB

PoC details

References

2