Description
Kentico CMS is an ASP.NET web content management system.
The Staging API is used to replicate data between production and development systems. If an attacker has valid credentials for the API, they can get full access to the system.
Remediation
Restrict access to the Staging API
References
Related Vulnerabilities
Session cookies scoped to parent domain
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4304)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4593)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3195)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-1499)