An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
History

Wed, 08 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-08T16:14:58.802Z

Reserved: 2023-05-22T00:00:00

Link: CVE-2023-33651

cve-icon Vulnrichment

Updated: 2024-08-02T15:47:06.520Z

cve-icon NVD

Status : Modified

Published: 2023-06-06T19:15:12.103

Modified: 2025-01-08T17:15:12.777

Link: CVE-2023-33651

cve-icon Redhat

No data.