The public database has exposed 184 million identification, including Microsoft, Facebook, Snapchat and government account connections


  • The CMS SiteCore had an account with a hard coded password
  • Threat actors could use it to download arbitrary files, making RCE
  • Thousands of termination criteria are potentially at risk

SiteCore Experience Platform, a business level content management system (CMS) has brought three vulnerabilities which, when chained, allowed the threat actors to take full control of vulnerable servers, the experts warned.

Watchtowr cybersecurity researchers have discovered that the first defect is a hard -coded password for an internal user – a single letter – ‘B’ – making it super easy to guess.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top