
A URL-encoded ASP .NET Cookieless marker could partially bypass the CVE-2023-36899 fix and cross IIS application boundaries. http://x.com/i/article/2087269856156467201
Post summary
The tweet indicates that a URL‑encoded ASP .NET Cookieless marker can partially bypass the CVE‑2023‑36899 fix, enabling cross‑application boundary attacks, but no evidence of active exploitation or PoC code is presented.
