Vulnerability Description
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sitecore | Cms | <= 9.1 |
Related Weaknesses (CWE)
References
- https://dev.sitecore.net/Downloads.aspxProductVendor Advisory
- https://www.synacktiv.com/blog.htmlThird Party Advisory
- https://www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdExploitPatchThird Party Advisory
- https://dev.sitecore.net/Downloads.aspxProductVendor Advisory
- https://www.synacktiv.com/blog.htmlThird Party Advisory
- https://www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdExploitPatchThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-US Government Resource
FAQ
What is CVE-2019-9875?
CVE-2019-9875 is a vulnerability with a CVSS score of 8.8 (HIGH). Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST paramet...
How severe is CVE-2019-9875?
CVE-2019-9875 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9875?
Check the references section above for vendor advisories and patch information. Affected products include: Sitecore Cms.