Description
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24819 | Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:37:16.572Z
Reserved: 2021-08-10T00:00:00.000Z
Link: CVE-2021-38366
No data.
Status : Modified
Published: 2021-08-12T21:15:09.377
Modified: 2024-11-21T06:16:55.003
Link: CVE-2021-38366
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD