High severity7.5NVD Advisory· Published Sep 15, 2024· Updated Jun 17, 2026
CVE-2024-46938
CVE-2024-46938
Description
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Affected products
7- cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:*Range: >=8.0,<=10.4
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:*range: >=8.0,<=10.4
- (no CPE)range: 8.0 Initial Release - 10.4 Initial Release
- Sitecore/Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC)description
- Range: 8.0 Initial Release - 10.4 Initial Release
- Range: 8.0 Initial Release - 10.4 Initial Release
Patches
Vulnerability mechanics
References
1- support.sitecore.com/kbnvdVendor Advisory
News mentions
0No linked articles in our index yet.