PT-2023-20571 · Sitecore · Sitecore Xp/Xm

Thomas Stern

·

Publicado

2023-03-14

·

Atualizado

2025-02-27

·

CVE-2023-26262

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sitecore XP/XM version 10.3
Description An issue exists where an authenticated Sitecore user can upload language files without restrictions, leading to direct code execution on the content management server.
Recommendations For Sitecore XP/XM version 10.3, consider restricting language file uploads to prevent direct code execution until a patch is available.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26262

Produtos afetados

Sitecore Xp/Xm