CVE-2023-33653: High severity Sitecore Experience Platform vulnerability
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33653?
CVE-2023-33653 is an authenticated remote code execution (RCE) vulnerability found in Sitecore Experience Platform (XP) version 9.3.
How severe is CVE-2023-33653?
CVE-2023-33653 has a severity rating of 8.8, indicating a high severity vulnerability.
Which component is affected by CVE-2023-33653?
The component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML in Sitecore Experience Platform (XP) version 9.3 is affected by CVE-2023-33653.
How can I fix CVE-2023-33653?
To fix CVE-2023-33653, you should apply the necessary security patches or upgrade to a version that does not contain the vulnerability.
Where can I find more information about CVE-2023-33653?
You can find more information about CVE-2023-33653 at the following reference: https://blog.assetnote.io/2023/05/10/sitecore-round-two/