Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/Invoke.aspx.
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.
Link | Tags |
---|---|
https://blog.assetnote.io/2023/05/10/sitecore-round-two/ | third party advisory exploit |