First published: Mon May 22 2023(Updated: )
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore | <=10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-27067.
The severity of CVE-2023-27067 is high, with a severity value of 7.5.
The affected software for CVE-2023-27067 is Sitecore Experience Platform through 10.2.
CVE-2023-27067 allows remote attackers to download arbitrary files via a crafted command to download.aspx by exploiting the directory traversal vulnerability in Sitecore Experience Platform through 10.2.
Yes, you can find more information about CVE-2023-27067 at the following links: [Link1](https://blogs.night-wolf.io/0-day-vulnerabilities-at-sitecore-pagedesigner) [Link2](https://dev.sitecore.net/Downloads/Sitecore%20Experience%20Platform/103/Sitecore%20Experience%20Platform%20103/Release%20Notes)