Sitecore XP
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*
- >= 7.5.0, <= 7.5.2
- >= 8.0.0, <= 8.0.7
- >= 8.1.0, <= 8.1.3
- >= 8.2.0, <= 8.2.7
This vulnerability is being actively exploited in the wild.
A remote code execution vulnerability has been identified in Sitecore Experience Platform (XP) versions 7.5 Initial Release to 8.2 Update-7. This vulnerability arises from an insecure deserialization issue in the Report.ashx file, which was used for the Executive Insight Dashboard, a feature that has been deprecated. The vulnerability allows unauthorized users to execute arbitrary code on the server where Sitecore is running.
Exploitation of this vulnerability allows for remote code execution on the affected server, with the executed code running under the NT AUTHORITY\NETWORK SERVICE account. This could potentially be escalated to SYSTEM level privileges.
The vulnerability can be reproduced by sending a crafted XML payload to the Report.ashx endpoint. The payload must include a 'parameters' XML tag containing a serialized object that exploits the deserialization vulnerability. This can be done using a tool like ysoserial.net to generate the malicious payload, which is then base64-encoded and included in the request.
Sitecore users are advised to upgrade to Sitecore XP 9.0.0 or higher, or to remove the Report.ashx file from the /sitecore/shell/ClientBin/Reporting/ directory on their server instances.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.