Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m57-4hqx-rgqv

Опубликовано: 25 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is already known via a specially-crafted URL. Affected files do not include .config, .aspx or .cs files. The issue does not allow for directory browsing.

Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is already known via a specially-crafted URL. Affected files do not include .config, .aspx or .cs files. The issue does not allow for directory browsing.

EPSS

Процентиль: 18%
0.00057
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-610

Связанные уязвимости

nvd
7 месяцев назад

Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is already known via a specially-crafted URL. Affected files do not include .config, .aspx or .cs files. The issue does not allow for directory browsing.

EPSS

Процентиль: 18%
0.00057
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-610