QID 730960
Date Published: 2024-02-05
QID 730960: Sitecore Remote Code Execution (RCE) Vulnerability
The TemplateParser is fundamental in ASP.NET Web Forms. It is used for parsing different ASP.NET source files such as .aspx and for parsing other input from various sources, including user provided data. The TemplateParser is capable of creating objects of arbitrary types using their public parameter-less constructors and invoking property setter methods on them. Multiple Sitecore products are vulnerable to RCE vulnerability due to the TemplateParser
Affected Products:
Experience Manager
Experience Platform
Experience Commerce
Managed Cloud
QID Detection Logic:
This QID sends an HTTP POST request to the 'sitecore_xaml.ashx/-/xaml/Sitecore.Xaml.Tutorials.Styles.Index' endpoint with a crafted payload in the request body and checks for code execution.
An unauthenticated, remote attacker could exploit this vulnerability to execute arbitrary code on the targeted system.
CVEs related to QID 730960
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB1002979 |
|