CVE-2023-27066: Path Traversal
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27066?
CVE-2023-27066 refers to a directory traversal vulnerability in Site Core Experience Platform 10.2 and earlier versions, allowing authenticated remote attackers to download arbitrary files via Urlhandle.
How severe is CVE-2023-27066?
CVE-2023-27066 has a severity rating of medium with a CVSS score of 6.5.
What is the affected software for CVE-2023-27066?
The affected software for CVE-2023-27066 is Site Core Experience Platform versions up to and including 10.2.
How can authenticated remote attackers exploit CVE-2023-27066?
Authenticated remote attackers can exploit CVE-2023-27066 by using directory traversal techniques to download arbitrary files via the Urlhandle.
Where can I find more information about CVE-2023-27066?
You can find more information about CVE-2023-27066 in the following references: - [https://blogs.night-wolf.io/0-day-vulnerabilities-at-sitecore-pagedesigner](https://blogs.night-wolf.io/0-day-vulnerabilities-at-sitecore-pagedesigner) - [https://dev.sitecore.net/Downloads/Sitecore%20Experience%20Platform/103/Sitecore%20Experience%20Platform%20103/Release%20Notes](https://dev.sitecore.net/Downloads/Sitecore%20Experience%20Platform/103/Sitecore%20Experience%20Platform%20103/Release%20Notes)