Files
CVEs-PoC/2016/CVE-2016-8855.md
2025-09-29 21:09:30 +02:00

847 B

CVE-2016-8855

Description

Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.

POC

Reference

Github