Description
A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
7.5 Initial Release (custom)
8.0 Initial Release (custom)
8.1 Initial Release (custom)
8.2 Initial Release (custom)
9.0 Initial Release (custom)
9.1 Initial Release (custom)
9.2 Initial Release
9.3 Initial Release
10.0 Initial Release (custom)
10.1 Initial Release (custom)
10.2 Initial Release
7.2 Initial Release (custom)
*
References
support.sitecore.com/...ticle_view&sysparm_article=KB1001489
support.sitecore.com/...ticle_view&sysparm_article=KB1001539
www.vulncheck.com/...ories/sitecore-xp-cms-managed-cloud-xss