Description

Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is already known via a specially-crafted URL. Affected files do not include .config, .aspx or .cs files. The issue does not allow for directory browsing.

INFO

Published Date :

2025-07-25T15:55:07.308Z

Last Modified :

2026-03-23T15:43:23.619Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2015-10142 vulnerability.

Vendors Products
Sitecore
  • Cms
  • Experience Platform
  • Sitecore

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability