First published: Thu Aug 12 2021(Updated: )
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore | <=10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38366.
The severity of CVE-2021-38366 is high with a score of 8.8.
CVE-2021-38366 impacts Sitecore versions up to and including 10.1.
Remote authenticated users can exploit CVE-2021-38366 by uploading arbitrary files and achieving remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
Yes, please refer to the provided reference link for information on how to fix CVE-2021-38366.