CVE-2024-46938
Sitecore Experience Platform , Manager, and Commerce Unauthenticated Arbitrary File Read
Record summary
CVE-2024-46938 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 7, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 17, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
experience_commerceBrowse Sitecore / experience_commerceDefault status: unknown | VulnCheck, CVE List | 8.0 to < 10.4 | affected |
experience_managerBrowse sitecore / experience_managerDefault status: unknown | CVE List | 8.0 to < 10.4 | affected |
experience_platformBrowse sitecore / experience_platformDefault status: unknown | CVE List | 8.0 to < 10.4 | affected |
Nuclei templates
1ProjectDiscoveryHIGHSitecore Experience Platform <= 10.4 - Arbitrary File ReadCVSS 7.5
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Impact
Unauthenticated attackers can read arbitrary files from the Sitecore server, potentially exposing sensitive configuration and credentials.
Remediation
Update Sitecore Experience Platform to a version that patches CVE-2024-46938.
Source: ProjectDiscovery