CVE-2023-26262

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
14/03/2023
Last modified:
27/02/2025

Description

An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:* 10.3 (including)
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:* 10.3 (excluding)