7.5
CVE-2025-53694
- EPSS 5.34%
- Veröffentlicht 03.09.2025 12:36:37
- Zuletzt bearbeitet 08.09.2025 18:11:15
- Quelle 9947ef80-c5d5-474a-bbab-97341a
- CVE-Watchlists
- Unerledigt
Information Disclosure in ItemServices API
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sitecore ≫ Experience Commerce Version >= 9.2 <= 10.4
Sitecore ≫ Experience Manager Version >= 9.2 <= 10.4
Sitecore ≫ Experience Platform Version >= 9.2 < 10.4
Sitecore ≫ Experience Platform Version10.4 Update-
Sitecore ≫ Managed Cloud Version-
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.34% | 0.916 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 9947ef80-c5d5-474a-bbab-97341a59000e | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003734
https://labs.watchtowr.com/cache-me-if-you-can-sitecore-experience-platform-cache-poisoning-to-rce/