CVE-2019-9874
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A security flaw in Sitecore CMS allows attackers to send specially crafted data that tricks the system into running malicious code without needing a login. This happens through the anti-CSRF protection feature, which should block unwanted requests but instead opens a backdoor.
Unsafe deserialization of untrusted .NET objects in the Sitecore.Security.AntiCSRF module enables remote code execution via the __CSRFTOKEN POST parameter. An unauthenticated attacker can serialize a malicious .NET gadget chain and execute arbitrary code with application privileges, affecting Sitecore CMS 7.0–7.2 and XP 7.5–8.2.
The full analysis of this CVE is available in Portuguese →