CVE-2017-9356: XSS
Published Jun 23, 2017
·Updated
Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI.
Affected Software
2 affected components
Sitecore Sitecore.NET=7.1
Sitecore Sitecore.NET=7.2
Event History
Jun 23, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9356?
CVE-2017-9356 is considered a moderate severity vulnerability due to its potential for Cross Site Scripting attacks.
2
How do I fix CVE-2017-9356?
To fix CVE-2017-9356, upgrade Sitecore.NET to version 7.3 or later, which addresses this vulnerability.
3
What are the affected versions of Sitecore for CVE-2017-9356?
CVE-2017-9356 affects Sitecore.NET versions 7.1 and 7.2.
4
What type of vulnerability is CVE-2017-9356?
CVE-2017-9356 is a Cross Site Scripting (XSS) vulnerability.
5
What is the impact of CVE-2017-9356 on web applications?
The impact of CVE-2017-9356 can lead to unauthorized script execution within the user's browser, compromising sensitive data.