← All CVEs

CVE-2024-46938

high · 7.5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

7.5
CVSS
46.8%
EPSS (exploit prob.)
99th
EPSS percentile
2024-09-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
sitecoreexperience_commerce>= 8.0, <= 10.4
sitecoreexperience_manager>= 8.0, <= 10.4
sitecoreexperience_platform>= 8.0, <= 10.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-46938