CVE-2021-38366
12.08.2021, 21:15
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.Enginsight
Vendor | Product | Version |
---|---|---|
sitecore | sitecore | 𝑥 ≤ 10.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration