The Hacker News 中文 关注 研究人员警告:Sitecore 漏洞链可导致缓存投毒和远程代码执行 Sitecore Experience Platform 中披露了三项新的安全漏洞,这些漏洞可能被利用来泄露信息和执行远程代码。根据 watchTowr Labs 的说法,这些漏洞如下:CVE-2025-53693 - 通过不安全的反射实现 HTML 缓存投毒 CVE-2025-53691 - 通过不安全的 deserialization 实现远程代码执行 (RCE) CVE-2025-53694 - Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution thehackernews.com Hacker & Security News on Bluesky @hacker.at.thenote.app bsky.app