PT-2017-16794 · Sitecore · Sitecore Cms

Published

2017-05-23

·

Updated

2017-06-08

·

CVE-2017-5966

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sitecore CRM version 8.1 Rev 151207
Description The issue allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack. This is achieved by exploiting the file parameter in the "sitecore/shell/download.aspx" API endpoint.
Recommendations For Sitecore CRM version 8.1 Rev 151207, consider restricting access to the sitecore/shell/download.aspx endpoint to prevent absolute path traversal attacks, and avoid using the file parameter until a fix is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5966

Affected Products

Sitecore Cms