Description
Kentico is an ASP.NET web content management system. The Staging API is used to replicate data between production and development systems.
Kentico Staging API contains an authentication bypass vulnerability that allows
unauthenticated remote attackers to access sensitive functionality, potentially leading to complete server compromise.
Remediation
Upgrade to the latest version of Kentico
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-4407)
Oracle JRE CVE-2017-10274 Vulnerability (CVE-2017-10274)
MySQL CVE-2023-21882 Vulnerability (CVE-2023-21882)
Static Nonce Identified in Content Security Policy (CSP)
Craft CMS Files or Directories Accessible to External Parties Vulnerability (CVE-2024-52292)