216.73.217.22

CVE-2025-2746

· Published 24/03/2025 19:15 · Modified 24/03/2025 19:15

Labels: CVE-2025-2746 2025-03-24CVE-2025-2746CWE-287[email protected]

Essential information

Published
24/03/2025 19:15
Modified
24/03/2025 19:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
kentico / xperience cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*

References