High severity8.8CISA KEVNVD Advisory· Published May 31, 2019· Updated Jun 17, 2026
CVE-2019-9875
CVE-2019-9875
Description
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Sitecore/Sitecoredescription
- Range: <=9.1
Patches
Vulnerability mechanics
References
4- www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdfnvdExploitPatchThird Party Advisory
- dev.sitecore.net/Downloads.aspxnvdProductVendor Advisory
- www.synacktiv.com/blog.htmlnvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.