VYPR

Sitecore

by Sitecore

CVEs (2)

  • CVE-2021-42237CriKEVNov 5, 2021
    risk 0.93cvss 9.8epss 0.98

    Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

  • CVE-2021-38366HigAug 12, 2021
    risk 0.57cvss 8.8epss 0.03

    Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.