ZeroHour

CVE-2023-27066

PoC
CVSS 3.1
6.5 medium
EPSS
1%p72
Published
()
Modified
Description

Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle.

Vendors
sitecore
Products
experience platform
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.