CVE-2023-35813 is a critical remote code execution vulnerability in Sitecore Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud (versions 8.2 through 10.3). The vulnerability arises from improper control of code generation (CWE-94) due to misuse of the ASP.NET TemplateParser. Attackers can supply crafted input to the TemplateParser.ParseTemplateInternal method, allowing instantiation of arbitrary types and invocation of property setters. This can be exploited to execute arbitrary code or exfiltrate sensitive data, for example by leveraging gadgets such as AssemblyInstaller (for remote assembly loading and code execution) or RemotingService (for data exfiltration). The attack does not require authentication or user interaction and can be triggered via crafted POST requests to sitecore_xaml.ashx endpoints. The vulnerability affects several internal Sitecore types that rely on the TemplateParser for control instantiation and property mapping.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a comprehensive Python proof-of-concept (PoC) exploit for CVE-2023-35813, a critical remote code execution (RCE) vulnerability in Sitecore. The repository consists of two files: a README.md with a brief title, and exploit.py, which contains the main exploit logic. The exploit.py script is a standalone Python3 tool that allows a user to specify a target Sitecore URL and optionally an InteractSH/Burp Collaborator URL for OOB testing. The script performs a series of tests against the target, attempting to exploit the RCE vulnerability by sending crafted HTTP requests. It checks for successful code execution and attempts to extract sensitive information such as database connection strings, highlighting any credentials found. The script provides detailed output, including vulnerability confirmation, impact assessment, and remediation recommendations. The exploit is a PoC and does not include a weaponized or customizable payload, but it demonstrates the ability to achieve RCE and information disclosure on vulnerable Sitecore instances.
This repository contains a Go-based exploit for CVE-2023-35813, targeting Sitecore instances. The main file, CVE-2023-35813.go, is a standalone exploit that takes a target URL as input and attempts to exploit a vulnerability in the /sitecore_xaml.ashx endpoint. The exploit works by sending specially crafted POST requests with malicious __PARAMETERS to trigger server-side parsing, first verifying if the target is vulnerable, and then attempting to extract sensitive database connection strings (web, master, core) if successful. The exploit uses Go's exec.Command to invoke curl for HTTP requests and processes the responses to determine vulnerability and extract data. The repository is structured simply, with a single code file, a README with usage instructions, and a .gitignore. The exploit is operational, providing both detection and data extraction capabilities, and is specifically tailored for Sitecore environments vulnerable to CVE-2023-35813.
This repository provides a proof-of-concept exploit for CVE-2023-35813, a critical remote code execution vulnerability in Sitecore. The exploit consists of two main Python scripts: 'command.py' and 'exploit.py'. The workflow is as follows: the attacker crafts a malicious ASP.NET payload (provided in 'command.txt' or 'commandRedirect.txt'), uses 'command.py' to custom URL-encode the payload, and saves the result to 'encodeout.txt'. The 'exploit.py' script then reads this encoded payload and sends it as a POST request to the vulnerable Sitecore endpoint '/sitecore_xaml.ashx/-/xaml/Sitecore.Xaml.Tutorials.Styles.Index' over HTTPS. The exploit leverages the template parser in Sitecore to register and invoke a .NET RemotingService, which can be abused for remote code execution or other server-side actions. The repository is structured for ease of use, with clear separation between payload creation/encoding and exploitation. No detection scripts or fake elements are present; the code is a functional POC exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.