
通过不安全的反序列化实现远程代码执行(RCE)
AjaxScriptManager 中的相同反射机制可用于调用 ProcessSerializedData 方法。该方法使用不安全的 BinaryFormatter 对提供的有效载荷进行反序列化,导致远程代码执行。攻击者可以构造恶意的序列化对象,在服务器上执行任意命令。
远程代码执行: 攻击者利用 CVE-2025-53691 在服务器上执行任意代码。
Sitecore 已为此漏洞发布补丁。强烈建议升级到最新版本的 Sitecore XP,或应用提供的安全补丁。
[1] Watchtowr Labs. (2025). Cache Me If You Can: Sitecore Experience Platform Cache Poisoning to RCE.