CVE-2023-33652: High severity Sitecore Experience Platform vulnerability
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/Invoke.aspx.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Sitecore Experience Platform (XP) vulnerability?
The vulnerability ID for this Sitecore Experience Platform (XP) vulnerability is CVE-2023-33652.
What is the severity of vulnerability CVE-2023-33652?
The severity of vulnerability CVE-2023-33652 is high with a severity value of 8.8.
What is the affected software version for vulnerability CVE-2023-33652?
The affected software version for vulnerability CVE-2023-33652 is Sitecore Experience Platform v9.3.
How does vulnerability CVE-2023-33652 impact Sitecore Experience Platform (XP)?
Vulnerability CVE-2023-33652 impacts Sitecore Experience Platform (XP) by allowing authenticated remote code execution (RCE) via the component /sitecore/shell/Invoke.aspx.
Is there a fix available for vulnerability CVE-2023-33652?
Yes, a fix is available for vulnerability CVE-2023-33652. It is recommended to update Sitecore Experience Platform (XP) to a patched version to mitigate the risk.