Web1 vuln-feed

Finding #64

Inventory item apache-test 2.4.37 (software, apache)
TitleSitecore CMS and Experience Platform (XP): Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:12Z
Last updated2026-06-11T07:35:12Z
Source advisorySitecore CMS and Experience Platform (XP): Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Update status