Authenticated Remote Code Execution Vulnerability in Sitecore Experience Platform
CVE-2023-33653

8.8HIGH

Key Information:

Vendor

Sitecore

Vendor
CVE Published:
6 June 2023

What is CVE-2023-33653?

An authenticated remote code execution vulnerability has been identified in Sitecore Experience Platform v9.3. The exploit allows attackers to execute arbitrary commands on the server by manipulating the endpoint at /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML. This vulnerability could lead to severe impacts on the integrity and security of affected systems.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.