CVE-2009-4367 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 6.1% (pctl 93)
Patch early
A public exploit exists.
Description
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 6.09% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-12-21 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sitecore | staging module |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sitecore Staging Module 5.4.0 - Authentication Bypass / File Manipulation | 2009-12-17 |
References
- http://osvdb.org/61147
- http://secunia.com/advisories/37763
- http://www.exploit-db.com/exploits/10513
- http://www.securityfocus.com/archive/1/508529/100/0/threaded
- http://www.securityfocus.com/bid/37388
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54881
- https://www.sec-consult.com/files/20091217-0_sitecore_StagingModule_1.0.txt
- http://osvdb.org/61147
- http://secunia.com/advisories/37763
- http://www.exploit-db.com/exploits/10513
- http://www.securityfocus.com/archive/1/508529/100/0/threaded
- http://www.securityfocus.com/bid/37388
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54881
- https://www.sec-consult.com/files/20091217-0_sitecore_StagingModule_1.0.txt
→ the Explorer · watch your stack · NVD