PT-2019-19909 · Sitecore · Sitecore

Published

2019-05-31

·

Updated

2025-04-04

·

CVE-2019-9875

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sitecore versions prior to 9.1
Description The issue allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter due to deserialization of untrusted data in the anti CSRF module.
Recommendations For versions prior to 9.1, update to version 9.1 or later to resolve the issue.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2019-9875

Affected Products

Sitecore