CVE-2024-46938

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/09/2024
Last modified:
20/09/2024

Description

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:* 8.0 (including) 10.4 (including)
cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:* 8.0 (including) 10.4 (including)
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:* 8.0 (including) 10.4 (including)