Vulnerability Description
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sitecore | Experience Platform | 9.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153613/Sitecore-9.0-Rev-171002-Cross-Site-SExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/153613/Sitecore-9.0-Rev-171002-Cross-Site-SExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-13493?
CVE-2019-13493 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScr...
How severe is CVE-2019-13493?
CVE-2019-13493 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13493?
Check the references section above for vendor advisories and patch information. Affected products include: Sitecore Experience Platform.