Loading
Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI.
Use CWE-79, Sitecore vendor hub and Sitecore.Net product page to widen CVE-2017-9356 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-7669 for nearby disclosures in the same product family.