Public database exposed 184 million credentials including Microsoft, Facebook, Snapchat and Government Account -Login


  • Sitecore CMS had an account with a hard -code password
  • Threat actors could use it to upload arbitrary files, obtain RCE
  • Thousands of endpoints are potentially at risk

Sitecore Experience Platform, a company level Content Management System (CMS) carried three vulnerabilities that, when linked together, allow threat actors full takeover of vulnerable servers, experts have warned.

CyberSecurity – Scientists Watchtowr found that the first error is a hard -coded password for an internal user – only one letter – ‘B’ – making it super easy to guess.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top