Sitecore

Experience Platform

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.66%
  • Veröffentlicht 22.05.2023 17:15:09
  • Zuletzt bearbeitet 31.01.2025 14:15:29

Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle.

Exploit
  • EPSS 10.97%
  • Veröffentlicht 14.03.2023 21:15:10
  • Zuletzt bearbeitet 27.02.2025 21:15:18

An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.

Warnung Exploit
  • EPSS 94.37%
  • Veröffentlicht 05.11.2021 10:15:08
  • Zuletzt bearbeitet 10.11.2025 14:43:39

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 17.07.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:25:00

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

Exploit
  • EPSS 41.77%
  • Veröffentlicht 06.06.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:29

Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized ob...

Warnung Exploit
  • EPSS 78.93%
  • Veröffentlicht 31.05.2019 21:29:06
  • Zuletzt bearbeitet 07.11.2025 19:36:12

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the H...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 19.03.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-...