Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g53h-cfhr-24hw

Опубликовано: 24 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

EPSS

Процентиль: 79%
0.01227
Низкий

7.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.2
nvd
11 месяцев назад

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

EPSS

Процентиль: 79%
0.01227
Низкий

7.2 High

CVSS3

Дефекты

CWE-22