Reflected XSS in Sitecore CMS Version 8.2 by Sitecore
CVE-2017-11439

5.4MEDIUM

Key Information:

Vendor

Sitecore

Status
Vendor
CVE Published:
19 July 2017

What is CVE-2017-11439?

In Sitecore CMS version 8.2, an issue has been identified that allows for reflected cross-site scripting (XSS) through the shell/Applications/Tools/Run Program parameter. This vulnerability can be exploited by an attacker to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions and data exposure. When user input is not adequately validated or sanitized, an attacker can manipulate URLs to execute harmful JavaScript in the context of the page, which can compromise security and user data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.