Cross Site Scripting Vulnerability in Sitecore.NET by Sitecore
CVE-2017-9356
6.1MEDIUM
What is CVE-2017-9356?
Sitecore.NET versions 7.1 and 7.2 are vulnerable to a Cross Site Scripting (XSS) attack through the 'searchStr' parameter in the '/Search-Results' URI. This allows an attacker to inject malicious scripts into pages viewed by other users, potentially compromising user data and session integrity. It is essential for users of these versions to apply appropriate security measures to mitigate the risk associated with this vulnerability.