Vulnerabilities
Vulnerable Software
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx
CVSS Score
7.5
EPSS Score
0.005
Published
2023-05-22
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle.
CVSS Score
6.5
EPSS Score
0.004
Published
2023-05-22
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.
CVSS Score
7.2
EPSS Score
0.08
Published
2023-03-14
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-07-17
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.
CVSS Score
8.8
EPSS Score
0.418
Published
2019-06-06


Contact Us

Shodan ® - All rights reserved