CVE-2017-5965: Medium severity sitecore vulnerability
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5965?
CVE-2017-5965 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2017-5965?
To fix CVE-2017-5965, update to a patched version of Sitecore CRM that addresses this vulnerability.
Who is affected by CVE-2017-5965?
CVE-2017-5965 affects remote authenticated administrators using Sitecore CRM 8.1 Rev 151207.
What type of vulnerability is CVE-2017-5965?
CVE-2017-5965 is a remote code execution vulnerability related to the package manager of Sitecore CRM.
Can CVE-2017-5965 be exploited without authentication?
No, CVE-2017-5965 can only be exploited by remote authenticated administrators.