Executive brief
Kentico Xperience (formerly Kentico CMS) fails to properly validate security headers in its staging service, allowing for the bypass of authentication. An attacker can provide malicious .NET object input that, when deserialized, leads to unauthenticated remote code execution on the hosting server.
Affected products
- Kentico Xperience (formerly Kentico CMS) 9.x versions; 10.0.x before 10.0.52; 11.0.x before 11.0.48; 12.0.x before 12.0.15
Timeline
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: disclosed
- 2020-05-06: other: Public exploit released on Packet Storm Security