PT-2017-9846 · Sitecore · Sitecore Experience Platform

Pralhad Chaskar

·

Publicado

2017-03-19

·

Atualizado

2017-03-21

·

CVE-2016-8855

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sitecore Experience Platform version 8.1 rev. 160519 (8.1 Update-3)
Description The issue allows remote attacks via the Name or Description parameter in the "/sitecore/client/Applications/List Manager/Taskpages/Contact list" endpoint. This is a Cross-Site Scripting (XSS) issue.
Recommendations For Sitecore Experience Platform version 8.1 rev. 160519 (8.1 Update-3), update to version 8.2 Update-2 to resolve the issue. As a temporary workaround, consider restricting access to the "/sitecore/client/Applications/List Manager/Taskpages/Contact list" endpoint and avoid using the Name or Description parameters until the update is applied.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8855

Produtos afetados

Sitecore Experience Platform