CVE-2023-26262 Details
Description
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.
A vulnerability allowing unrestricted language file uploads has been identified in Sitecore XP/XM version 10.3. This issue arises from the import languages functionality, which can be exploited by authenticated users to upload arbitrary files, such as web shells, that facilitate direct code execution on the content management server.
Implement file validation on the language import feature to restrict uploads to safe file types. Additionally, configure the upload directory to disallow code execution and consider adding a rule to the web.config file to block uploads of certain file types or to specific locations within the Sitecore application.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/istern/CVE-2023-26262 | CVE | ExploitMitigationThird Party Advisory |
| https://www.sitecore.com/trust | CVE | Vendor Advisory |
| https://github.com/istern/CVE-2023-26262 | [email protected] | ExploitMitigationThird Party Advisory |
| https://www.sitecore.com/trust | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sitecore experience manager | <= 10.3 |
CPE
Remediation
| |
| sitecore experience platform | < 10.3 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 27, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 10, 2023 | Reanalysis | [email protected] |
| Mar 23, 2023 | Reanalysis | [email protected] |
| Mar 20, 2023 | Initial Analysis | [email protected] |