CVE-2016-8855: XSS
Published Mar 19, 2017
·Updated
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.
Affected Software
1 affected component
Sitecore Experience Platform=8.1-rev._160519
Event History
Mar 19, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-8855?
CVE-2016-8855 has a moderate severity level due to the potential for remote attacks through Cross-Site Scripting (XSS).
2
How do I fix CVE-2016-8855?
You can fix CVE-2016-8855 by upgrading to Sitecore Experience Platform version 8.2 Update-2 or later.
3
What platforms are affected by CVE-2016-8855?
CVE-2016-8855 specifically affects Sitecore Experience Platform version 8.1 rev. 160519.
4
What attack vector is exploited in CVE-2016-8855?
CVE-2016-8855 is exploited through the Name or Description parameter in the Contact List page.
5
Can CVE-2016-8855 be exploited without authentication?
Yes, CVE-2016-8855 can be exploited by remote attackers without the need for authentication.