# ItemServices API 信息泄露漏洞
## 概述
存在敏感信息泄露漏洞(Exposure of Sensitive Information to an Unauthorized Actor),影响 Sitecore Experience Manager (XM) 和 Sitecore Experience Platform (XP)。
## 影响版本
- **Sitecore Experience Manager (XM)**:版本 9.2 至 10.4
- **Sitecore Experience Platform (XP)**:版本 9.2 至 10.4
## 细节
该漏洞允许未经授权的用户访问敏感信息,可能因配置不当或访问控制缺失导致。
## 影响
未经授权的攻击者可利用此漏洞获取本应受限的敏感数据,可能导致信息泄露,威胁系统安全与隐私保护。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | Information Disclosure in ItemService API with a restricted anonymous user, leading to exposure of cache keys using a brute-force approach | https://github.com/blueisbeautiful/CVE-2025-53694 | POC详情 |
2 | From Information Disclosure to RCE in Sitecore Experience Platform (XP) | https://github.com/blueisbeautiful/CVE-2025-53694-to-CVE-2025-53691 | POC详情 |
3 | Information Disclosure in ItemService API with a restricted anonymous user, leading to exposure of cache keys using a brute-force approach | https://github.com/brokendreamsclub/CVE-2025-53694 | POC详情 |
4 | From Information Disclosure to RCE in Sitecore Experience Platform (XP) | https://github.com/brokendreamsclub/CVE-2025-53694-to-CVE-2025-53691 | POC详情 |
暂无评论