CVE-2023-35813: Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

Description

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

Classification

CVE ID: CVE-2023-35813

Affected Products

Vendor: n/a

Product: n/a

Nuclei Template

http/cves/2023/CVE-2023-35813.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 91.67% (probability of being exploited)

EPSS Percentile: 99.18% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1002979

Timeline