Sitecore体验平台漏洞:版本10.1至10.3需要关键更新
bishopfox.com | 博客 | #rce | #vulnerability | #hardcoded-credentials | #sitecore | #cve-2025-34509 | #cms-security
摘要
watchTowr 披露 Sitecore Experience Platform 三个可串联漏洞:ServicesAPI 用户硬编码口令(默认密码为字母“b”)、ZIP slip 路径穿越及 PowerShell 扩展文件上传缺陷,组合可实现远程代码执行,10.1–10.3 版本需尽快升级。
- 发布时间
- 收录时间
Skip to content