vendor:
Sitecore Experience Platform
by:
abhishek morla
8.1
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Sitecore Experience Platform
Affected Version From: 9
Affected Version To: 10.3
Patch Exists: YES
Related CWE: CVE-2023-35813
CPE: a:sitecore:experience_platform:8.2
Platforms Tested: Windows 64-bit, Mozilla Firefox
2024
Sitecore – Remote Code Execution v8.2
The vulnerability in Sitecore versions 9.0 to 10.3 and 8.2 allows remote code execution, impacting all Experience Platform topologies (XM, XP, XC). An attacker can exploit this vulnerability to retrieve core connection strings. This vulnerability has been assigned CVE-2023-35813.
Mitigation:
Ensure the Sitecore installation is updated to the latest version and follow security best practices. Restrict network access to the Sitecore server.