漏洞描述 Sitecore是一款领先的数字体验管理平台,旨在帮助企业实现个性化、多渠道的数字营销和客户体验管理。Sitecore提供了一系列功能强大的工具和解决方案,包括内容管理、个性化营销、电子商务、数据分析等,帮助企业创建和管理富有吸引力的网站、移动应用和在线商店。多个Sitecore产品存在远程代码执行漏洞。影响产品如下:ExperienceManager, Experience Platform, and Experience Commerce。
相关漏洞推荐 POC CVE-2021-42237: Sitecore Experience Platform Pre-Auth RCE POC CVE-2023-35813: Sitecore - Remote Code Execution POC CVE-2024-46938: Sitecore Experience Platform <= 10.4 - Arbitrary File Read POC CVE-2025-27218: Sitecore Experience Manager (XM)/Experience Platform (XP) 10.4 - Insecure Deserialization POC CVE-2023-35813: Sitecore - Remote Code Execution POC CVE-2014-100004: Sitecore CMS - Cross-Site Scripting POC CVE-2019-9874: Sitecore Experience Platform - Deserialization of Untrusted Data POC sitecore-debug-page: SiteCore Debug Page POC sitecore-lfi: Sitecore 9.3 - Webroot File Read POC CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials Sitecore 反序列化漏洞(CVE-2025-27218) Sitecore CMS bundle 任意文件读取漏洞 Sitecore CMS /-/speak/v1/bundles/bundle.js 文件读取漏洞(CVE-2024-46938)