ZeroHour

CVE-2023-33651

PoC
CVSS 3.1
7.5 high
EPSS
1%p72
Published
()
Modified
Description

An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.

Vendors
sitecore
Products
experience commerce, experience manager, experience platform, managed cloud
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.