Description
Kentico is an ASP.NET web content management system. The Staging API is used to replicate data between production and development systems.
Kentico Staging API contains an authentication bypass vulnerability that allows
unauthenticated remote attackers to access sensitive functionality, potentially leading to complete server compromise.
Remediation
Upgrade to the latest version of Kentico
References
Related Vulnerabilities
Microsoft IIS5 NTLM and Basic authentication bypass
Atlassian Jira Observable Discrepancy Vulnerability (CVE-2020-4028)
Oracle Database Server Other Vulnerability (CVE-2007-2119)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3225)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-24554)