Record summary

CVE-2024-46938 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 17, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

VulnCheck, CVE List8.0 to < 10.4affected

Default status: unknown

CVE List8.0 to < 10.4affected

Default status: unknown

CVE List8.0 to < 10.4affected

Nuclei templates

1
ProjectDiscoveryHIGHSitecore Experience Platform <= 10.4 - Arbitrary File ReadCVSS 7.5

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

Impact

Unauthenticated attackers can read arbitrary files from the Sitecore server, potentially exposing sensitive configuration and credentials.

Remediation

Update Sitecore Experience Platform to a version that patches CVE-2024-46938.

AuthorsDhiyaneshDK
Template tagscvecve2024sitecorelfircevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:*
Shodan: http.title:"sitecore"
FOFA: title="sitecore"
Google: intitle:"sitecore"

Source: ProjectDiscovery

References

2