Path Traversal Vulnerability in Sitecore CMS 8.2
CVE-2017-11440
4.9MEDIUM
What is CVE-2017-11440?
In Sitecore CMS 8.2, an attacker can exploit a path traversal vulnerability through the 'fi' parameter in the shell/Applications/Layouts/IDE.aspx and the 'Reference' parameter in admin/LinqScratchPad.aspx. This flaw can be leveraged to access unauthorized files on the server, potentially exposing sensitive information.