CVE-2024-46938
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
7.5
CVSS
46.8%
EPSS (exploit prob.)
99th
EPSS percentile
2024-09-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sitecore | experience_commerce | >= 8.0, <= 10.4 |
| sitecore | experience_manager | >= 8.0, <= 10.4 |
| sitecore | experience_platform | >= 8.0, <= 10.4 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-46938