Description
Due to the exposed TemplateParser in the Sitecore site, an attacker can create a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of Sitecore
References
Security Bulletin SC2023-002-576660
Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)
Related Vulnerabilities
OpenSSL Improper Certificate Validation Vulnerability (CVE-2019-1552)
MySQL CVE-2019-2624 Vulnerability (CVE-2019-2624)
Oracle Database Server CVE-2010-0900 Vulnerability (CVE-2010-0900)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-41585)
PHP Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-7272)