vendor:
Sitecore
by:
abhishek morla
8.1
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Sitecore
Affected Version From: 9.0 Initial Release
Affected Version To: 10.3 Initial Release
Patch Exists: YES
Related CWE: CVE-2023-35813
CPE: a:sitecore:sitecore
Platforms Tested: Windows 64-bit, Mozilla Firefox
2024
Sitecore – Remote Code Execution v8.2
The vulnerability exists in Sitecore version 8.2 and affects all Experience Platform topologies (XM, XP, XC) from 9.0 Initial Release to 10.3 Initial Release. An attacker can exploit this vulnerability to execute arbitrary code remotely. CVE-2023-35813 has been assigned to this vulnerability.
Mitigation:
To mitigate this vulnerability, it is recommended to upgrade to a patched version of Sitecore. Regularly update the software to the latest secure version.