cisa-warns-of-sitecore-rce-flaws;-active-exploits-hit-next.js-and-draytek-devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included two six-year-old security weaknesses affecting Sitecore CMS and Experience Platform (XP) in its Known Exploited Vulnerabilities (KEV) catalog, citing proof of ongoing exploitation.
The weaknesses are outlined below –

CVE-2019-9874 (CVSS score: 9.8) – A deserialization weakness in the Sitecore.Security.AntiCSRF


Leave a Reply

Your email address will not be published. Required fields are marked *

Share This