CVE-2019-9874criticalunder attackCWE-502

CVE-2019-9874

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 84%
from disclosure to weapon
Published on NVDMay 31
CISA KEV+2126d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2025-04-16

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

A security flaw in Sitecore CMS allows attackers to send specially crafted data that tricks the system into running malicious code without needing a login. This happens through the anti-CSRF protection feature, which should block unwanted requests but instead opens a backdoor.

Technical detail

Unsafe deserialization of untrusted .NET objects in the Sitecore.Security.AntiCSRF module enables remote code execution via the __CSRFTOKEN POST parameter. An unauthenticated attacker can serialize a malicious .NET gadget chain and execute arbitrary code with application privileges, affecting Sitecore CMS 7.0–7.2 and XP 7.5–8.2.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a