CVE-2023-26262

CVSS V2 None CVSS V3 None
Description
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.
Overview
  • CVE ID
  • CVE-2023-26262
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-14T21:15:10
  • Last Modified Date
  • 2023-04-10T17:39:03
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:* 1 OR 10.3
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:* 1 OR 10.3
References
Reference URL Reference Tags
https://github.com/istern/CVE-2023-26262 Exploit Mitigation Third Party Advisory
https://www.sitecore.com/trust Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 06:29:21 Added to TrackCVE
2023-04-17 06:29:23 Weakness Enumeration new