Loading
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
Use CWE-502, Sitecore vendor hub and Cms product page to widen CVE-2019-9875 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-9874, CVE-2019-11198 and CVE-2017-11439 for nearby disclosures in the same product family.