Description
Due to the exposed TemplateParser in the Sitecore site, an attacker can create a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of Sitecore
References
Security Bulletin SC2023-002-576660
Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)
Related Vulnerabilities
Roundcube Improper Input Validation Vulnerability (CVE-2011-1492)
Oracle Database Server CVE-2008-0347 Vulnerability (CVE-2008-0347)
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-36095)
MySQL CVE-2018-2813 Vulnerability (CVE-2018-2813)
e107 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-16388)