A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.
History

Thu, 31 Jul 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Sitecore
Sitecore cms
Sitecore experience Platform
Sitecore managed Cloud
Sitecore sitecore
Vendors & Products Sitecore
Sitecore cms
Sitecore experience Platform
Sitecore managed Cloud
Sitecore sitecore

Fri, 25 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.
Title Sitecore XP 7.5 - 10.2, CMS 7.2, and Managed Cloud XSS
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-07-25T15:55:36.039Z

Updated: 2025-07-25T17:43:58.975Z

Reserved: 2025-07-24T15:19:26.600Z

Link: CVE-2022-4979

cve-icon Vulnrichment

Updated: 2025-07-25T17:39:53.725Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-25T16:15:27.230

Modified: 2025-07-29T14:14:55.157

Link: CVE-2022-4979

cve-icon Redhat

No data.