Description
Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is already known via a specially-crafted URL. Affected files do not include .config, .aspx or .cs files. The issue does not allow for directory browsing.
References (3)
Scores
CVSS v4
6.9
EPSS
0.0009
EPSS Percentile
25.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-610
Status
published
Products (3)
Sitecore/Content Management System (CMS)
< 7.2 Update-3 (rev. 141226)
Sitecore/Content Management System (CMS)
< 7.5 Update-1 (rev. 150130)
Sitecore/Experience Platform (XP)
< 8.0 Initial Release (rev. 141212)
Published
Jul 25, 2025
Tracked Since
Feb 18, 2026