The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included two long-standing security vulnerabilities affecting Sitecore CMS and Experience Platform (XP) in its list of Known Exploited Vulnerabilities (KEV), following reports of active exploitation.
Below are the details of the identified vulnerabilities:
Below are the details of the identified vulnerabilities:
CVE-2019-9874 (CVSS score: 9.8) – An issue related to deserialization in the Sitecore.Security.AntiCSRF
