ZeroHour

CVE-2023-27068

PoC
CVSS 3.1
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.

Vendors
sitecore
Products
experience platform
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.