Vulnerability Description
Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sitecore | Crm | 8.1 |
Related Weaknesses (CWE)
References
- http://research.aurainfosec.io/disclosures/2017-05-18-sitecore/ExploitThird Party Advisory
- http://research.aurainfosec.io/disclosures/2017-05-18-sitecore/ExploitThird Party Advisory
FAQ
What is CVE-2017-5966?
CVE-2017-5966 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.
How severe is CVE-2017-5966?
CVE-2017-5966 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5966?
Check the references section above for vendor advisories and patch information. Affected products include: Sitecore Crm.