CVE-2021-38366: Malicious File Upload
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure Update Center is disabled in Sitecore (10.1) to prevent remote authenticated users from uploading arbitrary files and triggering remote code execution via an uploaded .aspx file at an admin/Packages URL.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38366.
What is the severity of CVE-2021-38366?
The severity of CVE-2021-38366 is high with a score of 8.8.
How does CVE-2021-38366 impact Sitecore versions?
CVE-2021-38366 impacts Sitecore versions up to and including 10.1.
How can remote authenticated users exploit CVE-2021-38366?
Remote authenticated users can exploit CVE-2021-38366 by uploading arbitrary files and achieving remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
Is there a fix available for CVE-2021-38366?
Yes, please refer to the provided reference link for information on how to fix CVE-2021-38366.