Public database exposed 184 million credentials including Microsoft, Facebook, Snapchat, and government account logins




  • The Sitecore CMS had an account with a hardcoded password
  • Threat actors could use it to upload arbitrary files, achieving RCE
  • Thousands of endpoints are potentially at risk

Sitecore Experience Platform, an enterprise-level content management system (CMS) carried three vulnerabilities which, when chained together, allowed threat actors full takeover of vulnerable servers, experts have warned.

Cybersecurity researchers watchTowr found the first flaw is a hardcoded password for an internal user – just one letter – ‘b’ – making it super easy to guess.

https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img