CVE-2023-33651

📊 7.5 HIGH0.4%🎯 0 exploits
📅 Published Jun 6, 2023
📋 Status: Modified

An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.

🎯 Affected Products & Systems

4 product configurations affected

Filter by type:
📱
Vulnerable
Version: ≥ 9.0 ∧ ≤ 10.3
CPE:
cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:*
📱
Vulnerable
Version: ≥ 9.0 ∧ ≤ 10.3
CPE:
cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:*
📱
Vulnerable
Version: ≥ 9.0 ∧ ≤ 10.3
CPE:
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:*
📱
Application
Vulnerable
Version: All versions
CPE:
cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:*
Metrics
7.5 HIGHCVSS v3.1[email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector:
NETWORK
Complexity:
LOW
Privileges:
NONE
User Interaction:
NONE
Confidentiality:
HIGH
Integrity:
NONE
Availability:
NONE
Scope:
UNCHANGED

🔍 Technical Details

Analysis Status
Modified
CVSS Details
7.5 (HIGH)v3.1
EPSS Details
0.4% (Minimal)59.6th percentile
Last updated: Oct 31, 2025
Exploitation probability within 30 days
Published Date
Jun 6, 2023 (2 years ago)
Last Modified
Jan 8, 2025 (9 months ago)
Security Weaknesses2
References2