Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2749

Опубликовано: 24 мар. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
Версия до 13.0.178 (включая)

EPSS

Процентиль: 79%
0.01227
Низкий

7.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.2
github
11 месяцев назад

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

EPSS

Процентиль: 79%
0.01227
Низкий

7.2 High

CVSS3

Дефекты

CWE-22