CVE-2017-11440: Sitecore CMS

Medium severity, CVSS 4.9. EPSS: 2% chance of exploitation in the next 30 days.

In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.

Affected products

Published 2017-07-19. Last modified 2026-06-17.