CNNVD-202507-3277 Information

CNNVD ID

CNNVD-202507-3277

CVE-2015-10142

  • CNNVD Published: 2025-07-25

Description (Chinese)

Sitecore Experience Platform(XP)是丹麦Sitecore公司的一套客户数字体验平台。 Sitecore Experience Platform(XP)存在安全漏洞,该漏洞源于特制URL可能导致文件下载。

Description (English)

Sitecore Exchange Platform (XP) is a customer digital experience platform for the Danish company Sitecore. There is a security loophole in Sitecore Exchange Platform (XP), which originates from a unique URL that may result in the downloading of documents.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Sitecore

Published

2025-07-25

Last Modified

2026-02-24

References

https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB0816762 https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002377 https://www.vulncheck.com/advisories/sitecore-xp-cms-file-read-via-known-path https://access.redhat.com/security/cve/cve-2015-10142

Patch

https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB0816762

Share on: