Description
Kentico CMS is an ASP.NET web content management system.
Kentico CMS API uses .NET deserialization of user-supplied data. Arbitrary object deserialization is inherently unsafe, and should never be performed on untrusted data.
Remediation
Upgrade to the latest version of Kentico CMS
References
Related Vulnerabilities
Invision Power Board version 3.3.4 unserialize PHP code execution
Oracle Weblogic Async Component Deserialization RCE CVE-2019-2725
Oracle Weblogic WLS-WSAT Component Deserialization RCE
XML external entity injection via File Upload
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-11619)