CVE-2019-13493: Sitecore Experience Platform
Medium severity, CVSS 5.4. EPSS: 1.6% chance of exploitation in the next 30 days.
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
Affected products
- Sitecore Experience Platform: version 9.0 only
Published 2019-07-17. Last modified 2026-06-17.