CVE-2019-9875
KEV PoC moderateAuthenticated .NET Deserialization RCE in Sitecore CMS and XP
CISA: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE-2019-9875 is an insecure deserialization flaw (CWE-502) in the anti-CSRF module of Sitecore CMS and Experience Platform (XP) through version 9.1. An authenticated attacker can trigger it by sending a crafted serialized .NET object in an HTTP POST parameter, which the module deserializes without validation. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 8.8, network-adjacent attack requiring valid low-privilege credentials). Any organization running an affected Sitecore CMS or XP version is exposed, with risk concentrated in enterprise deployments; related reporting has also highlighted a hard-coded password issue in Sitecore XP that could ease attacker access. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-03-26, indicating active exploitation in the wild, and EPSS assigns a 14.0% chance of exploitation within 30 days.
What to do: Apply the Sitecore security patch for this deserialization issue per the vendor's bulletin, following CISA KEV required actions (including BOD 22-01 guidance for federal agencies). Because exploitation requires valid credentials, audit and harden Sitecore accounts (including checking for default or hard-coded credentials given related reports) and review access logs for authenticated POST requests carrying unusual serialized payloads to the anti-CSRF endpoint. If patching is not immediately possible, restrict access to the Sitecore instance at the network layer and monitor for exploitation indicators.
| Sitecore CMS and Experience Platform (XP) | through 9.1 (fixed versions not specified in the available data; apply the patch per Sitecore's security bulletin) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
- Affected
- Sitecore CMS and Experience Platform (XP)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sitecore
- Products
- cms
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H