Junglewise Threat Intelligence

CVE-2019-9875: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

CVE-2019-9875 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-03-26

Technologies: Sitecore CMS, Sitecore Experience Platform (XP). Vendors: Sitecore.

Executive brief

Sitecore CMS and Experience Platform (XP) through version 9.1 contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module. An authenticated attacker can execute arbitrary code by sending a malicious serialized .NET object via the __CSRFTOKEN HTTP POST parameter.

Affected products

  • Sitecore CMS up to and including 9.1
  • Sitecore Experience Platform (XP) up to and including 9.1

Timeline

  • 2019-05-31: disclosed: NVD Published Date
  • 2025-03-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-26: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats