Description
Due to the exposed TemplateParser in the Sitecore site, an attacker can create a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of Sitecore
References
Security Bulletin SC2023-002-576660
Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4550)
Plone CMS Resource Management Errors Vulnerability (CVE-2013-4188)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13663)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29214)