VYPR
Medium severityNVD Advisory· Published Jul 25, 2025· Updated Apr 15, 2026

CVE-2022-4979

CVE-2022-4979

Description

A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated XSS vulnerability in Sitecore XP 7.5–10.2 and CMS 7.2 allows attackers to trick Shell users into executing arbitrary JavaScript.

A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 through 10.2, as well as Sitecore CMS 7.2 through 7.2 Update-6. The flaw occurs in the Sitecore Shell interface and stems from insufficient sanitization of user-supplied input, allowing the injection of arbitrary JavaScript code into a page that other authenticated users may view.

To exploit this vulnerability, an attacker must be an authenticated user of the Sitecore Shell. They craft a malicious payload that, when delivered to a victim (also authenticated to the Sitecore Shell), executes in the victim's browser within the context of the vulnerable application. The attack requires user interaction as the victim must access a crafted link or view malicious content. Managed Cloud Standard customers running the affected Sitecore Experience Platform or CMS versions are also impacted [1].

Successful exploitation enables the attacker to execute arbitrary JavaScript in the browser of the targeted authenticated user. This can lead to actions performed on behalf of the victim within the Sitecore Shell, including data theft, session hijacking, or other malicious operations that affect the confidentiality and integrity of the Sitecore instance.

Sitecore has addressed the issue in newer versions of the affected products. Users are strongly advised to upgrade to a patched release. For Managed Cloud Standard customers, applying the latest updates is recommended to mitigate the risk [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.