Executive brief
Sitecore XP is vulnerable to an insecure deserialization attack that allows for unauthenticated remote command execution. The vulnerability exists in the handling of untrusted data, requiring no special configuration to exploit.
Affected products
- Sitecore Experience Platform (XP) 7.5 Initial Release to 8.2 Update-7
Timeline
- 2021-11-02: disclosed: Public disclosure by Assetnote
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: exploited: Reported as exploited in the wild