CVE-2019-13493
MEDIUMSitecore XP 9.0.171002 Authenticated Stored XSS in Media Library
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-13493. PoCs published by Owais Mehtab.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Sitecore CMS 9.0 rev 171002, where the file extension parameter is not properly escaped. An attacker can inject malicious scripts via the media library's extension input field, potentially affecting administrators, users, or editors.
Description
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Sitecore CMS 9.0 rev 171002, where the file extension parameter is not properly escaped. An attacker can inject malicious scripts via the media library's extension input field, potentially affecting administrators, users, or editors.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N