Sitecore.net
by Sitecore
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42237 | Cri | 0.93 | 9.8 | 0.98 | KEV | Nov 5, 2021 | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability. | |
| CVE-2019-9874 | Cri | 0.82 | 9.8 | 0.84 | KEV | May 31, 2019 | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter… | |
| CVE-2019-9875 | Hig | 0.70 | 8.8 | 0.14 | KEV | May 31, 2019 | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter. | |
| CVE-2019-11080 | Hig | 0.61 | 8.8 | 0.14 | Jun 6, 2019 | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object. | ||
| CVE-2021-38366 | Hig | 0.57 | 8.8 | 0.03 | Aug 12, 2021 | Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL. | ||
| CVE-2018-7669 | Hig | 0.53 | 7.5 | 0.17 | Apr 27, 2018 | An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a… | ||
| CVE-2017-9356 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2017 | Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. | ||
| CVE-2019-13493 | Med | 0.38 | 5.4 | 0.02 | Jul 17, 2019 | In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript. | ||
| CVE-2017-11439 | Med | 0.35 | 5.4 | 0.01 | Jul 19, 2017 | In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter. |
- risk 0.93cvss 9.8epss 0.98
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
- risk 0.82cvss 9.8epss 0.84
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter…
- risk 0.70cvss 8.8epss 0.14
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
- risk 0.61cvss 8.8epss 0.14
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.
- risk 0.57cvss 8.8epss 0.03
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
- risk 0.53cvss 7.5epss 0.17
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a…
- risk 0.40cvss 6.1epss 0.01
Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI.
- risk 0.38cvss 5.4epss 0.02
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
- risk 0.35cvss 5.4epss 0.01
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.