CVE-2019-9875: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
Other sources
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter CSRFTOKEN.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9875?
CVE-2019-9875 is a vulnerability in the anti CSRF module in Sitecore through 9.1 that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
How does CVE-2019-9875 affect Sitecore?
CVE-2019-9875 affects Sitecore through version 9.1, allowing an authenticated attacker to execute arbitrary code.
What is the severity of CVE-2019-9875?
CVE-2019-9875 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2019-9875?
An attacker can exploit CVE-2019-9875 by sending a serialized .NET object in an HTTP POST parameter, allowing them to execute arbitrary code.
Is there a fix for CVE-2019-9875?
Yes, Sitecore has released a fix for CVE-2019-9875. It is recommended to update to the latest version to mitigate the vulnerability.