CVE-2009-4367

Sitecore Staging Module <5.4.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4367. PoCs published by L. Weichselbaum.

AI-analyzed exploit summary This advisory details an authentication bypass vulnerability in Sitecore Staging Module, allowing arbitrary file upload, download, directory listing, and cache clearing via the Staging Webservice. The exploit leverages improper authentication checks in SOAP requests to the API endpoint.

Description

The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by L. Weichselbaum · textwebappswindows
https://www.exploit-db.com/exploits/10513

This advisory details an authentication bypass vulnerability in Sitecore Staging Module, allowing arbitrary file upload, download, directory listing, and cache clearing via the Staging Webservice. The exploit leverages improper authentication checks in SOAP requests to the API endpoint.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sitecore Staging Module <= 5.4.0 rev.080625
No auth needed
Prerequisites: Access to the Staging Webservice endpoint · Network connectivity to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/10513
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37763
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/508529/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37388
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/61147
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54881

Scores

EPSS 0.0672
EPSS Percentile 91.4%

Details

CWE
CWE-287
Status published
Products (1)
sitecore/staging_module < 5.4.0
Published Dec 21, 2009
Tracked Since Feb 18, 2026