CVE-2022-4979: Sitecore XP 7.5 - 10.2, CMS 7.2, and Managed Cloud XSS
A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4979?
CVE-2022-4979 is classified as a cross-site scripting (XSS) vulnerability, which can lead to significant security risks for affected users.
How do I fix CVE-2022-4979?
To fix CVE-2022-4979, upgrade Sitecore Experience Platform to version 10.3 or later and Sitecore CMS to version 7.2 Update-7 or later.
Who is affected by CVE-2022-4979?
CVE-2022-4979 affects authenticated users of Sitecore Experience Platform versions 7.5 to 10.2 and Sitecore CMS version 7.2 to 7.2 Update-6.
What are the implications of CVE-2022-4979?
The implications of CVE-2022-4979 include the potential for attackers to execute malicious JavaScript code in the context of authenticated Sitecore Shell users.
Is CVE-2022-4979 still present in newer versions of Sitecore?
CVE-2022-4979 has been resolved in newer versions of Sitecore, specifically in Sitecore Experience Platform 10.3 and Sitecore CMS 7.2 Update-7.