漏洞描述 Sitecore CMS 是丹麦 Sitecore 公司开发的一套在线营销内容管理系统(CMS),支持内容编辑、多语言、多网站部署及数字资产管理等功能。该漏洞允许未经身份验证的攻击者通过特制的 HTTP 请求读取服务器上的文件,可能导致敏感信息泄露,包括服务器配置文件、用户数据等。
相关漏洞推荐 POC CVE-2021-42237: Sitecore Experience Platform Pre-Auth RCE POC CVE-2023-35813: Sitecore - Remote Code Execution POC CVE-2024-46938: Sitecore Experience Platform <= 10.4 - Arbitrary File Read POC CVE-2025-27218: Sitecore Experience Manager (XM)/Experience Platform (XP) 10.4 - Insecure Deserialization POC CVE-2023-35813: Sitecore - Remote Code Execution POC CVE-2014-100004: Sitecore CMS - Cross-Site Scripting POC CVE-2019-9874: Sitecore Experience Platform - Deserialization of Untrusted Data POC sitecore-debug-page: SiteCore Debug Page POC sitecore-lfi: Sitecore 9.3 - Webroot File Read POC CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials Sitecore 反序列化漏洞(CVE-2025-27218) SiteCore 文件读取漏洞(CVE-2024-46938) Sitecore CMS bundle 任意文件读取漏洞