CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) – Hardcoded Credentials

CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials-渗透云记 - 专注于网络安全与技术分享
CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) – Hardcoded Credentials
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-34509: Sitecore ExperieNCe Manager (XM) and Experience Platform (XP) – Hardcoded Credentials

漏洞描述

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享