CVE-2023-27067: Path Traversal
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-27067.
What is the severity of CVE-2023-27067?
The severity of CVE-2023-27067 is high, with a severity value of 7.5.
What is the affected software for CVE-2023-27067?
The affected software for CVE-2023-27067 is Sitecore Experience Platform through 10.2.
How does CVE-2023-27067 work?
CVE-2023-27067 allows remote attackers to download arbitrary files via a crafted command to download.aspx by exploiting the directory traversal vulnerability in Sitecore Experience Platform through 10.2.
Are there any references or additional information available for CVE-2023-27067?
Yes, you can find more information about CVE-2023-27067 at the following links: [Link1](https://blogs.night-wolf.io/0-day-vulnerabilities-at-sitecore-pagedesigner) [Link2](https://dev.sitecore.net/Downloads/Sitecore%20Experience%20Platform/103/Sitecore%20Experience%20Platform%20103/Release%20Notes)