Executive brief
Sitecore CMS and Experience Platform (XP) through version 9.1 contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module. An authenticated attacker can execute arbitrary code by sending a malicious serialized .NET object via the __CSRFTOKEN HTTP POST parameter.
Affected products
- Sitecore CMS up to and including 9.1
- Sitecore Experience Platform (XP) up to and including 9.1
Timeline
- 2019-05-31: disclosed: NVD Published Date
- 2025-03-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-26: exploited: Reported as exploited in the wild in CISA KEV catalog