CVE-2023-33651

An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-06 19:15

Updated : 2025-01-08 17:15


NVD link : CVE-2023-33651

Mitre link : CVE-2023-33651

CVE.ORG link : CVE-2023-33651


JSON object : View

Products Affected

sitecore

  • managed_cloud
  • experience_commerce
  • experience_manager
  • experience_platform
CWE
CWE-863

Incorrect Authorization