First published: Tue Jun 06 2023(Updated: )
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore | >=9.0<=10.3 | |
Sitecore CMS and Experience Platform (XP) | >=9.0<=10.3 | |
Sitecore | >=9.0<=10.3 | |
Sitecore |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33651 is an issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release that allows attackers to bypass authorization rules.
CVE-2023-33651 affects Sitecore Experience Commerce versions 9.0 to 10.3, Sitecore Experience Manager versions 9.0 to 10.3, Sitecore Experience Platform versions 9.0 to 10.3, and Sitecore Managed Cloud.
CVE-2023-33651 has a severity of high (7.5).
Attackers can exploit CVE-2023-33651 by bypassing authorization rules in the MVC Device Simulator of the affected Sitecore products.
You can find more information about CVE-2023-33651 at the following references: [1] https://blog.assetnote.io/2023/05/10/sitecore-round-two/ [2] https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002925