First published: Tue May 23 2017(Updated: )
Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5966 is classified as a high-severity vulnerability due to its ability to allow remote authenticated administrators to exploit file traversal weaknesses.
To fix CVE-2017-5966, apply the latest security patches provided by Sitecore for CRM version 8.1.
CVE-2017-5966 can facilitate an absolute path traversal attack, which might allow sensitive file exposure.
Yes, CVE-2017-5966 specifically affects Sitecore CRM version 8.1.
Remote authenticated administrators using Sitecore CRM 8.1 are primarily affected by CVE-2017-5966.