CVE-2019-13493: Sitecore Experience Platform

Medium severity, CVSS 5.4. EPSS: 1.6% chance of exploitation in the next 30 days.

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

Affected products

  • Sitecore Experience Platform: version 9.0 only

Published 2019-07-17. Last modified 2026-06-17.