CVE-2023-27068: Critical severity sitecore vulnerability
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27068?
CVE-2023-27068 is a vulnerability that allows remote attackers to run arbitrary code in Sitecore Experience Platform through version 10.2.
How severe is CVE-2023-27068?
CVE-2023-27068 has a severity rating of 9.8, which is considered critical.
How does CVE-2023-27068 work?
CVE-2023-27068 occurs due to the deserialization of untrusted data in Sitecore Experience Platform, allowing remote attackers to execute arbitrary code via ValidationResult.aspx.
Which versions of Sitecore Experience Platform are affected by CVE-2023-27068?
Sitecore Experience Platform versions up to but excluding 10.2 are affected by CVE-2023-27068.
How can I mitigate CVE-2023-27068?
To mitigate CVE-2023-27068, it is recommended to update Sitecore Experience Platform to a version that is not affected by the vulnerability.