Tech

Public database exposed 184 million credentials including Microsoft, Facebook, Snapchat, and government account logins

Share
Share


  • The Sitecore CMS had an account with a hardcoded password
  • Threat actors could use it to upload arbitrary files, achieving RCE
  • Thousands of endpoints are potentially at risk

Sitecore Experience Platform, an enterprise-level content management system (CMS) carried three vulnerabilities which, when chained together, allowed threat actors full takeover of vulnerable servers, experts have warned.

Cybersecurity researchers watchTowr found the first flaw is a hardcoded password for an internal user – just one letter – ‘b’ – making it super easy to guess.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Some AI prompts could cause 50 times more CO₂ emissions than others, researchers find
Tech

Some AI prompts could cause 50 times more CO₂ emissions than others, researchers find

Credit: Sanket Mishra from Pexels No matter which questions we ask an...

Google Gemini’s super-fast Flash-Lite 2.5 model is out now – here’s why you should switch today
Tech

Google Gemini’s super-fast Flash-Lite 2.5 model is out now – here’s why you should switch today

Google’s new Gemini 2.5 Flash-Lite model is its fastest and most cost-efficient...

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up
Tech

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up

There’s nothing quite like the excitement of a new console; feverishly whipping...