Loading
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
Use CWE-287, Sitecore vendor hub and Rocks product page to widen CVE-2019-12440 into its surrounding weakness, vendor, and product context.