First published: Tue Jun 06 2023(Updated: )
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore | =9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33653 is an authenticated remote code execution (RCE) vulnerability found in Sitecore Experience Platform (XP) version 9.3.
CVE-2023-33653 has a severity rating of 8.8, indicating a high severity vulnerability.
The component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML in Sitecore Experience Platform (XP) version 9.3 is affected by CVE-2023-33653.
To fix CVE-2023-33653, you should apply the necessary security patches or upgrade to a version that does not contain the vulnerability.
You can find more information about CVE-2023-33653 at the following reference: https://blog.assetnote.io/2023/05/10/sitecore-round-two/