More

    Public database exposed 184 million credentials including Microsoft, Facebook, Snapchat, and government account logins




    • The Sitecore CMS had an account with a hardcoded password
    • Threat actors could use it to upload arbitrary files, achieving RCE
    • Thousands of endpoints are potentially at risk

    Sitecore Experience Platform, an enterprise-level content management system (CMS) carried three vulnerabilities which, when chained together, allowed threat actors full takeover of vulnerable servers, experts have warned.

    Cybersecurity researchers watchTowr found the first flaw is a hardcoded password for an internal user – just one letter – ‘b’ – making it super easy to guess.

    https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img