Sitecore CMS platforms through version 9.1 contain a deserialization vulnerability in the anti-CSRF module that allows authenticated attackers to execute arbitrary code via HTTP POST parameters. This vulnerability is actively exploited in the wild and affects a widely deployed web content management platform.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2019-05-31
Added to CISA KEV: 2025-03-26 2126 DAYS BETWEEN CVE AND KEV
CVE-2019-9875 is a security vulnerability affecting Sitecore CMS and XP platforms [1]. Below is a summary of the known details regarding this vulnerability.
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code. ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secuโฆ