Remote Command Injection Vulnerability in Sitecore Rocks Plugin
CVE-2019-12440
9.8CRITICAL
What is CVE-2019-12440?
The Sitecore Rocks plugin, prior to version 2.1.149, contains a vulnerability that permits unauthenticated attackers to execute arbitrary commands through the Hard Rocks Service. This flaw can lead to serious security breaches, enabling the injection of harmful code, which may compromise the integrity and confidentiality of the affected system.