漏洞描述 Sitecore是丹麦Sitecore公司的一套在线营销内容管理系统。Sitecore存在远程代码执行漏洞,此漏洞是由于Sitecore.Xaml.Tutorials.Styles.Index接口对用户的请求验证不当导致的。
相关漏洞推荐 POC aem-anonymous-write: Adobe Experience Manager (AEM) - Anonymous JCR Node Creation (CVE-2025-54253)Adobe Experience Manager配置错误导致任意代码执行漏洞 (CVE-2025-54251)Adobe Experience Manager XML注入漏洞导致安全功能绕过 (CVE-2025-54249) Adobe Experience Manager SSRF漏洞导致安全功能绕过 POC CVE-2019-16469: Adobe Experience Manager - Expression Language Injection POC CVE-2019-8086: Adobe Experience Manager - XML External Entity Injection POC CVE-2021-27748: IBM WebSphere HCL Digital Experience - Server-Side Request Forgery POC CVE-2021-42237: Sitecore Experience Platform Pre-Auth RCE POC CVE-2023-35813: Sitecore - Remote Code Execution POC CVE-2024-46938: Sitecore Experience Platform <= 10.4 - Arbitrary File Read POC CVE-2025-27218: Sitecore Experience Manager (XM)/Experience Platform (XP) 10.4 - Insecure Deserialization POC CVE-2023-35813: Sitecore - Remote Code Execution POC aem-felix-console: Adobe Experience Manager Felix Console - Default Login