RaqibCTI
CVE

CVE-2019-9875

P2
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Sitecore · CMS and Experience Platform (XP)
Date added (CISA)
2025-03-26
Remediation due
2025-04-16
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Source: NVD ↗ · CISA KEV Catalog ↗