Логотип exploitDog
bind:CVE-2025-2749
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-2749

Количество 2

Количество 2

nvd логотип

CVE-2025-2749

11 месяцев назад

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-g53h-cfhr-24hw

11 месяцев назад

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-2749

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

CVSS3: 7.2
1%
Низкий
11 месяцев назад
github логотип
GHSA-g53h-cfhr-24hw

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

CVSS3: 7.2
1%
Низкий
11 месяцев назад

Уязвимостей на страницу