File Upload Vulnerability in Sitecore by Sitecore
CVE-2021-38366
8.8HIGH
What is CVE-2021-38366?
Sitecore versions up to 10.1 with the Update Center enabled are susceptible to a vulnerability that allows authenticated users to upload arbitrary files. This can lead to remote code execution if a malicious user accesses an uploaded .aspx file via the admin/Packages URL, potentially compromising the integrity and security of the affected system.