CVE-2023-35813

EUVD-2023-39808
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
sitecoreexperience_commerce
8.2 ≤
𝑥
≤ 10.3
sitecoreexperience_manager
8.2 ≤
𝑥
≤ 10.3
sitecoreexperience_platform
8.2 ≤
𝑥
≤ 10.3
sitecoremanaged_cloud
8.2 ≤
𝑥
≤ 10.3
𝑥
= Vulnerable software versions