5.4
CVSSv3

CVE-2019-13493

Published: 17/07/2019 Updated: 18/07/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sitecore experience platform 9.0

Exploits

# Exploit Title: Stored Cross Site Scripting (XSS) in Sitecore 90 rev 171002 # Date: July 11, 2019 # Exploit Author: Owais Mehtab # Vendor Homepage: wwwsitecorenet/en # Version: 90 rev 171002 # Tested on: Sitecore Experience Platform 81 Update-3 ie; 81 rev 160519 # CVE : CVE-2019-13493 Vendor Description ------------------ Sitecor ...
Sitecore version 90 rev 171002 suffers from a persistent cross site scripting vulnerability ...