7.5
CVSSv2

CVE-2019-10068

Published: 26/03/2019 Updated: 15/04/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Kentico 12.0.x prior to 12.0.15, 11.0.x prior to 11.0.48, 10.0.x prior to 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kentico kentico