An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
References
Link | Resource |
---|---|
https://blog.assetnote.io/2023/05/10/sitecore-round-two/ | Exploit Third Party Advisory |
https://blog.assetnote.io/2023/05/10/sitecore-round-two/ | Exploit Third Party Advisory |
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002925 | Vendor Advisory |
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002925 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.assetnote.io/2023/05/10/sitecore-round-two/ - Exploit, Third Party Advisory | |
References | () https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002925 - Vendor Advisory |
16 Jun 2023, 16:54
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
First Time |
Sitecore experience Manager
Sitecore Sitecore experience Platform Sitecore experience Commerce Sitecore managed Cloud |
|
CWE | CWE-863 | |
CPE | cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:* cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:* |
|
References | (MISC) https://blog.assetnote.io/2023/05/10/sitecore-round-two/ - Exploit, Third Party Advisory | |
References | (MISC) https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002925 - Vendor Advisory |
06 Jun 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-06 19:15
Updated : 2025-01-08 17:15
NVD link : CVE-2023-33651
Mitre link : CVE-2023-33651
JSON object : View
Products Affected
sitecore
- experience_commerce
- experience_platform
- experience_manager
- managed_cloud
CWE
CWE-863
Incorrect Authorization