CVE-2023-33651

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 6, 2023
Updated: Jan 8, 2025
CWE ID 863

Summary

CVE-2023-33651 is a vulnerability affecting Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) versions 9.0 to 13.0 Initial Release. This issue lies within the MVC Device Simulator, enabling unauthorized access by bypassing authorization rules. Attackers can exploit this weakness to gain unauthorized access to restricted areas, potentially leading to data theft or system compromise. Sitecore urges users to apply the available patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sitecore Experience Platform
  • Sitecore Experience Manager

Affected Vendors

  • Sitecore Holding II A/S