vendor:
Sitecore Experience Platform
by:
abhishek morla
8.1
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Sitecore Experience Platform
Affected Version From: 9.0 Initial Release
Affected Version To: 10.3 Initial Release
Patch Exists: NO
Related CWE: CVE-2023-35813
CPE: a:sitecore:experience_platform
Platforms Tested: Windows 64-bit, Mozilla Firefox
2024
Sitecore – Remote Code Execution v8.2
The vulnerability impacts all Sitecore Experience Platform topologies (XM, XP, XC) from version 9.0 to 10.3 Initial Release, including version 8.2. An attacker can execute arbitrary code by sending a crafted payload to the sitecore_xaml.ashx endpoint. This vulnerability is identified as CVE-2023-35813.
Mitigation:
To mitigate this vulnerability, it is recommended to update Sitecore to a patched version or apply vendor-supplied security fixes. Additionally, restrict network access to the vulnerable endpoint to trusted sources only.