In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
| Software | From | Fixed in |
|---|---|---|
| sitecore / experience_platform | 9.0 | 9.0.x |