Directory Traversal Vulnerability in Sitecore Experience Platform
CVE-2023-27067

7.5HIGH

Key Information:

Vendor

Sitecore

Vendor
CVE Published:
22 May 2023

What is CVE-2023-27067?

A directory traversal vulnerability exists in the Sitecore Experience Platform, allowing remote attackers to exploit misconfigurations through specially crafted requests targeting the download.aspx endpoint. This weakness enables malicious users to access and download arbitrary files from the server, potentially exposing sensitive information and compromising the integrity of the web application. Users are highly urged to apply security patches and regularly audit their systems to prevent exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.