← Back to browse · API

CVE-2019-9875

Severity
HIGH
CVSS
8.8
EPSS
0.14154
Risk score
65.15
CISA KEV
Yes
PoC
No
Published
2019-05-31
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-19231, GHSA-7GVQ-J6PG-875G
Products
Sitecore:CMS and Experience Platform (XP), n/a:n/a n/a
Sources
cisa.gov CVE-2019-9875
euvd EUVD-2019-19231

Description

Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.

References