Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxvc-763r-j974

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.

EPSS

Процентиль: 15%
0.00047
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 месяцев назад

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.

EPSS

Процентиль: 15%
0.00047
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-862