Public database exposed 184 million credentials, including Microsoft's session, Facebook, Snapchat and government accounts


  • The CMS Sitecore had an account with a encoded password
  • Threat actors could use it to load arbitrary files, achieving RCE
  • Thousands of final points are potentially at risk

Sitecore Experience Platform, a business level management system (CMS) brought three vulnerabilities that, when they chain together, allowed the threat actors acquisition of vulnerable servers, experts warned.

Watchtowr cybersecurity researchers discovered that the first defect is a encoded password for an internal user, only one letter, 'B', which makes it very easy to guess.

scroll to top