Unrated severityCISA KEVNVD Advisory· Published May 31, 2019· Updated Oct 21, 2025
CVE-2019-9875
CVE-2019-9875
Description
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Sitecore/Sitecoredescription
- Range: <=9.1
Patches
Vulnerability mechanics
References
3- dev.sitecore.net/Downloads.aspxmitrex_refsource_MISC
- www.synacktiv.com/blog.htmlmitrex_refsource_MISC
- www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.