Tech

Public database exposed 184 million credentials including Microsoft, Facebook, Snapchat, and government account logins

Share
Share


  • The Sitecore CMS had an account with a hardcoded password
  • Threat actors could use it to upload arbitrary files, achieving RCE
  • Thousands of endpoints are potentially at risk

Sitecore Experience Platform, an enterprise-level content management system (CMS) carried three vulnerabilities which, when chained together, allowed threat actors full takeover of vulnerable servers, experts have warned.

Cybersecurity researchers watchTowr found the first flaw is a hardcoded password for an internal user – just one letter – ‘b’ – making it super easy to guess.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up
Tech

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up

There’s nothing quite like the excitement of a new console; feverishly whipping...

Websites are tracking you via browser fingerprinting, researchers show
Tech

Websites are tracking you via browser fingerprinting, researchers show

Credit: Pixabay/CC0 Public Domain Clearing your cookies is not enough to protect...

Psycholinguist talks nonsense to ChatGPT to understand how it processes language
Tech

Psycholinguist talks nonsense to ChatGPT to understand how it processes language

Credit: Pixabay/CC0 Public Domain A new study appearing in PLOS One by...