Vulnerability Description
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sitecore | Crm | 8.1 |
References
- http://research.aurainfosec.io/disclosures/2017-05-18-sitecore/ExploitThird Party Advisory
- http://research.aurainfosec.io/disclosures/2017-05-18-sitecore/ExploitThird Party Advisory
FAQ
What is CVE-2017-5965?
CVE-2017-5965 is a vulnerability with a CVSS score of 6.7 (MEDIUM). The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, vi...
How severe is CVE-2017-5965?
CVE-2017-5965 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5965?
Check the references section above for vendor advisories and patch information. Affected products include: Sitecore Crm.