Unrated severityCISA KEVNVD Advisory· Published May 31, 2019· Updated Oct 21, 2025
CVE-2019-9875
CVE-2019-9875
Description
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
Affected products
1- Sitecore/Sitecoredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- dev.sitecore.net/Downloads.aspxmitrex_refsource_MISC
- www.synacktiv.com/blog.htmlmitrex_refsource_MISC
- www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.