Описание
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-27068
- https://blogs.night-wolf.io/0-day-vulnerabilities-at-sitecore-pagedesigner
- https://dev.sitecore.net/Downloads/Sitecore%20Experience%20Platform/103/Sitecore%20Experience%20Platform%20103/Release%20Notes
- https://www.sitecore.com/products/sitecore-experience-platform
Связанные уязвимости
CVSS3: 9.8
nvd
больше 2 лет назад
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.