CVE-2009-4367
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear…
Does this matter?
Lower severity and a low EPSS score (6.09%). Track it; it rarely justifies an emergency change on its own.
Description
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 6.09% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- sitecore/staging module
- Source
- cve@mitre.org
References
- http://osvdb.org/61147
- http://secunia.com/advisories/37763Vendor Advisory
- http://www.exploit-db.com/exploits/10513Exploit
- http://www.securityfocus.com/archive/1/508529/100/0/threaded
- http://www.securityfocus.com/bid/37388Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54881
- https://www.sec-consult.com/files/20091217-0_sitecore_StagingModule_1.0.txtExploit
- http://osvdb.org/61147
- http://secunia.com/advisories/37763Vendor Advisory
- http://www.exploit-db.com/exploits/10513Exploit
- http://www.securityfocus.com/archive/1/508529/100/0/threaded
- http://www.securityfocus.com/bid/37388Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54881
- https://www.sec-consult.com/files/20091217-0_sitecore_StagingModule_1.0.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.