Sitecore
cpe:2.3:a:sitecore:cms:*:*:*:*:*:*:*
- <= 9.1.0
This vulnerability is being actively exploited in the wild.
A deserialization vulnerability has been identified in the anti-CSRF module of Sitecore CMS and Experience Platform (XP) versions through 9.1. This vulnerability allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter. In Sitecore versions 8.x, this vulnerability can be exploited without authentication, while in versions 9.x prior to 9.1.1, authentication is required.
Exploitation of this vulnerability allows for arbitrary code execution on the server.
The vulnerability can be reproduced by sending a POST request to a Sitecore application with a serialized .NET object in the __CSRFTOKEN parameter. The anti-CSRF module will deserialize the object, leading to remote code execution.
Sitecore has released a patch for versions prior to 9.0. For versions 9.0 and above, users should update to the latest version 9.1 Update-1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.