First published: Tue Mar 14 2023(Updated: )
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore CMS and Experience Platform (XP) | <=10.3 | |
Sitecore | <10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26262 is a vulnerability in Sitecore XP/XM 10.3 that allows an authenticated user to upload a language file and execute arbitrary code on the content management (CM) server.
CVE-2023-26262 has a severity rating of 7.2, which is considered high.
The CVE-2023-26262 vulnerability can be exploited by an authenticated Sitecore user who uploads a language file containing malicious code.
The affected software version of CVE-2023-26262 is Sitecore Experience Manager and Sitecore Experience Platform up to version 10.3.
Yes, Sitecore has released a fix for CVE-2023-26262. It is recommended to upgrade to the latest version of Sitecore XP/XM.