PT-2023-24432 · Sitecore · Sitecore Experience Commerce+2

Dylan Pindur

·

Published

2023-06-06

·

Updated

2025-01-08

·

CVE-2023-33651

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sitecore Experience Platform (XP) versions 9.0 Initial Release through 13.0 Initial Release Sitecore Experience Manager (XM) versions 9.0 Initial Release through 13.0 Initial Release Sitecore Experience Commerce (XC) versions 9.0 Initial Release through 13.0 Initial Release
Description An issue in the MVC Device Simulator allows attackers to bypass authorization rules.
Recommendations For Sitecore Experience Platform (XP) versions 9.0 Initial Release through 13.0 Initial Release, update to a version that includes a fix for this issue. For Sitecore Experience Manager (XM) versions 9.0 Initial Release through 13.0 Initial Release, update to a version that includes a fix for this issue. For Sitecore Experience Commerce (XC) versions 9.0 Initial Release through 13.0 Initial Release, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the MVC Device Simulator until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-33651

Affected Products

Sitecore Experience Commerce
Sitecore Experience Manager
Sitecore Experience Platform