Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 12.0.29
A vulnerability allowing unrestricted file uploads has been identified in Kentico Xperience versions through 12.0.29. This issue allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can exploit this vulnerability by manipulating file names to upload potentially malicious files, leading to unauthorized file uploads on the system.
Exploitation of this vulnerability could result in unauthorized file uploads, potentially allowing for the execution of malicious files on the server.
Users can upgrade to Kentico Xperience version 13.0.198 or later, where this vulnerability has been addressed. Instructions for applying the hotfix are available on the Kentico Xperience documentation site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.