CVE-2021-42237
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
- Affected products
- Sitecore Xp
- Sitecore Experience Platform
- = 7.5, 8.0, 8.1, 8.2
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 97.9% (100th percentile)
- Weakness
- CWE-502
- NVD status
- Analyzed
- Published
- 2021-11-05
CVE-2021-42237 at NVD
7 known exploits for CVE-2021-42237
Proof-of-concept code and exploit modules indexed by Sploitus