CVE-2019-9875: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
Other sources
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter CSRFTOKEN.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Operational
Inventory Sitecore CMS and Experience Platform (XP) deployments and identify any installations running Sitecore through 9.1 (i.e., versions up to and including 9.1).
Event History
Frequently Asked Questions
What is CVE-2019-9875?
CVE-2019-9875 is a vulnerability in the anti CSRF module in Sitecore through 9.1 that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
How does CVE-2019-9875 affect Sitecore?
CVE-2019-9875 affects Sitecore through version 9.1, allowing an authenticated attacker to execute arbitrary code.
What is the severity of CVE-2019-9875?
CVE-2019-9875 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2019-9875?
An attacker can exploit CVE-2019-9875 by sending a serialized .NET object in an HTTP POST parameter, allowing them to execute arbitrary code.
Is there a fix for CVE-2019-9875?
Yes, Sitecore has released a fix for CVE-2019-9875. It is recommended to update to the latest version to mitigate the vulnerability.