Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is already known via a specially-crafted URL. Affected files do not include .config, .aspx or .cs files. The issue does not allow for directory browsing.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sitecore
Sitecore cms Sitecore experience Platform Sitecore sitecore |
|
Vendors & Products |
Sitecore
Sitecore cms Sitecore experience Platform Sitecore sitecore |
Fri, 25 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is already known via a specially-crafted URL. Affected files do not include .config, .aspx or .cs files. The issue does not allow for directory browsing. | |
Title | Sitecore XP < 8.0 and CMS < 7.2 and < 7.5 File Read via Known Path | |
Weaknesses | CWE-610 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-25T15:55:07.308Z
Updated: 2025-07-25T17:59:33.517Z
Reserved: 2025-07-24T13:58:09.937Z
Link: CVE-2015-10142

Updated: 2025-07-25T17:59:30.368Z

Status : Awaiting Analysis
Published: 2025-07-25T16:15:26.663
Modified: 2025-07-29T14:14:55.157
Link: CVE-2015-10142

No data.