PoC Index

CVE-2019-13493

MEDIUM 5.4EPSS 1.6%

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

CVSS v3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
1.58% chance of exploitation in the next 30 days, 74th percentile
Published
2019-07-17
Updated
2024-08-04

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related