menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Technology News

>

One of the...
source image

Tech Radar

3w

read

422

img
dot

Image Credit: Tech Radar

One of the world's most popular CMS tools has an embarrassing security flaw, so patch immediately

  • The Sitecore Experience Platform, a popular CMS, had vulnerabilities that allowed threat actors to take over vulnerable servers.
  • One of the vulnerabilities was a hardcoded password for an internal user, making it easy to guess.
  • Malicious users could authenticate via an alternate login path to gain access to internal endpoints.
  • A 'Zip Slip' flaw in Sitecore Upload Wizard allowed authenticated attackers to upload malicious files.
  • Attackers could write arbitrary files in the webroot due to insufficient path sanitation.
  • With the Sitecore PowerShell Extensions module installed, attackers could achieve a 'reliable RCE'.
  • Around 22,000 publicly exposed Sitecore instances are vulnerable, from versions 10.1 to 10.4.
  • It is advised to patch immediately as attackers could potentially exploit these vulnerabilities.
  • No reports of abuse have been seen in the wild, but users are recommended to update as soon as possible.

Read Full Article

like

25 Likes

For uninterrupted reading, download the app