CVE-2024-46938
Sitecore Experience Platform (XP) vulnerability analysis and mitigation

Overview

An unauthenticated file read vulnerability (CVE-2024-46938) was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) versions 8.0 Initial Release through 10.4 Initial Release. The vulnerability allows an unauthenticated attacker to read arbitrary files from the local system (NVD, Assetnote).

Technical details

The vulnerability exists due to an order of operations issue in the code where input is not properly normalized before verification. The /-/speak/v1/bundles/bundle.js endpoint allows for arbitrary file read if an absolute path is used. The query parameter specifying the file is not properly normalized before verification, and the input is modified after verification, resulting in file extension checks being bypassable. For example, Web.Config#.js will be converted to just Web.Config after validation (Assetnote).

Impact

The vulnerability can lead to disclosure of sensitive files like web.config which often contains machine keys and Telerik encryption keys. This information disclosure can typically lead to command execution through deserializing a ViewState crafted after obtaining the machineKey value. An attacker can also use this vulnerability to download Sitecore backups containing DLL files with custom code that could lead to additional vulnerabilities (Assetnote).

Mitigation and workarounds

Sitecore patched this vulnerability in August 2024 as announced in their Security Bulletin SC2024-001-619349 (Assetnote).

Additional resources


SourceThis report was generated using AI

Related Sitecore Experience Platform (XP) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53693CRITICAL9.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-53690CRITICAL9
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
YesNoSep 03, 2025
CVE-2025-53691HIGH8.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-53694HIGH7.5
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2022-4979MEDIUM5.1
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoJul 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management