CVE-2017-11440: Path Traversal
Published Jul 19, 2017
·Updated
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.
Affected Software
1 affected component
Sitecore CMS=8.2
Event History
Jul 19, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11440?
CVE-2017-11440 is classified as a medium severity vulnerability due to its path traversal capabilities that can lead to unauthorized file access.
2
How do I fix CVE-2017-11440?
To fix CVE-2017-11440, it is recommended to upgrade to a more recent version of Sitecore CMS that has addressed these vulnerabilities.
3
Which Sitecore versions are affected by CVE-2017-11440?
CVE-2017-11440 specifically affects Sitecore CMS versions 8.2.
4
What are the implications of CVE-2017-11440?
The implications of CVE-2017-11440 include potential unauthorized file access, which can lead to sensitive data exposure.
5
Is CVE-2017-11440 related to web application security?
Yes, CVE-2017-11440 is a web application vulnerability that involves path traversal risks in the Sitecore CMS.