PT-2017-9846 · Sitecore · Sitecore Experience Platform
Pralhad Chaskar
·
Publicado
2017-03-19
·
Atualizado
2017-03-21
·
CVE-2016-8855
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sitecore Experience Platform version 8.1 rev. 160519 (8.1 Update-3)
Description
The issue allows remote attacks via the
Name or Description parameter in the "/sitecore/client/Applications/List Manager/Taskpages/Contact list" endpoint. This is a Cross-Site Scripting (XSS) issue.Recommendations
For Sitecore Experience Platform version 8.1 rev. 160519 (8.1 Update-3), update to version 8.2 Update-2 to resolve the issue. As a temporary workaround, consider restricting access to the "/sitecore/client/Applications/List Manager/Taskpages/Contact list" endpoint and avoid using the
Name or Description parameters until the update is applied.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sitecore Experience Platform