CISA Adds Sitecore CMS Code Execution Vulnerability to Exploited List

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

CISA Adds Sitecore CMS Code Execution Vulnerability to Exploited List

Post by Shane1145 »

The Cybersecurity and Infrastructure Security Agency (CISA) has included a critical deserialization vulnerability affecting Sitecore CMS and Experience Platform (XP).

This vulnerability, tracked as CVE-2019-9874, allows unauthenticated attackers to execute arbitrary code by manipulating HTTP POST parameters, specifically the __CSRFTOKEN field.


https://gbhackers.com/sitecore-cms-code ... erability/
Post Reply