The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included two six-year-old security weaknesses affecting Sitecore CMS and Experience Platform (XP) in its Known Exploited Vulnerabilities (KEV) catalog, citing proof of ongoing exploitation.
The weaknesses are outlined below –
CVE-2019-9874 (CVSS score: 9.8) – A deserialization weakness in the Sitecore.Security.AntiCSRF
