Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-03-19T18:00:00

Updated: 2024-08-06T02:35:02.225Z

Reserved: 2016-10-18T00:00:00

Link: CVE-2016-8855

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-03-19T18:59:00.163

Modified: 2017-03-21T14:30:19.570

Link: CVE-2016-8855

cve-icon Redhat

No data.