Junglewise Threat Intelligence

CVE-2019-9874: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

CVE-2019-9874 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-03-26

Technologies: Sitecore CMS, Sitecore Experience Platform (XP). Vendors: Sitecore.

Executive brief

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module. An unauthenticated remote attacker can execute arbitrary code by sending a malicious serialized .NET object via the __CSRFTOKEN HTTP POST parameter.

Affected products

  • Sitecore CMS 7.0 to 7.2
  • Sitecore Experience Platform (XP) 7.5 to 8.2

Timeline

  • 2019-05-31: disclosed: NVD Published Date
  • 2025-03-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats