Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-100662. PoCs published by abhishek morla.
AI-analyzed exploit summary This exploit leverages a deserialization vulnerability in Sitecore's XAML parser to execute arbitrary code by injecting a malicious payload via the `__PARAMETERS` field, leading to remote code execution (RCE). The payload uses ASP.NET controls to extract connection strings from the target system.
Description
Sitecore - Remote Code Execution v8.2
Exploits (1)
This exploit leverages a deserialization vulnerability in Sitecore's XAML parser to execute arbitrary code by injecting a malicious payload via the `__PARAMETERS` field, leading to remote code execution (RCE). The payload uses ASP.NET controls to extract connection strings from the target system.