peter bassill · operator
$ cve CVE-2019-13493 JSON

CVE-2019-13493 EXPLOIT

5.4
MEDIUM · CVSS 3.0 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

Scoring

CVSS5.4 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS1.58% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2019-07-17
Last modified2026-06-17

Affected (1)

VendorProduct
sitecoreexperience platform

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD