PT-2017-9846 · Sitecore · Sitecore Experience Platform
Pralhad Chaskar
·
Published
2017-03-19
·
Updated
2017-03-21
·
CVE-2016-8855
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sitecore Experience Platform version 8.1 rev. 160519 (8.1 Update-3)
Description
The issue allows remote attacks via the
Name or Description parameter in the "/sitecore/client/Applications/List Manager/Taskpages/Contact list" endpoint. This is a Cross-Site Scripting (XSS) issue.Recommendations
For Sitecore Experience Platform version 8.1 rev. 160519 (8.1 Update-3), update to version 8.2 Update-2 to resolve the issue. As a temporary workaround, consider restricting access to the "/sitecore/client/Applications/List Manager/Taskpages/Contact list" endpoint and avoid using the
Name or Description parameters until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sitecore Experience Platform