CVE-2019-9874 | Sitecore CMS/XP Sitecore.Security.AntiCSRF __CSRFTOKEN deserialization
A vulnerability was found in Sitecore CMS and XP and classified as critical. This issue affects some unknown processing of the component Sitecore.Security.AntiCSRF. The manipulation of the argument __CSRFTOKEN as part of POST Parameter leads to deserialization.
The identification of this vulnerability is CVE-2019-9874. The attack may be initiated remotely. There is no exploit available.