Metrics
Affected Vendors & Products
Thu, 16 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* |
Mon, 24 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Mon, 24 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178. | |
| Title | Kentico Xperience Staging media files upload authenticated remote code execution | |
| Weaknesses | CWE-22 CWE-434 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-03-24T18:18:07.228Z
Updated: 2025-03-24T19:16:31.029Z
Reserved: 2025-03-24T16:39:22.986Z
Link: CVE-2025-2749
Updated: 2025-03-24T18:44:16.090Z
Status : Analyzed
Published: 2025-03-24T19:15:52.400
Modified: 2025-10-17T10:32:54.807
Link: CVE-2025-2749
No data.