Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 12.0.60
A vulnerability allowing access control bypass has been identified in Kentico Xperience versions through 12.0.60. This vulnerability enables administrators to alter global administrator user privileges by sending unauthorized requests. As a result, attackers could potentially compromise global administrator accounts and disrupt security-sensitive macros by changing user privilege levels.
Exploitation of this vulnerability could lead to unauthorized modification of global administrator privileges, allowing attackers to compromise administrator accounts and interfere with security-sensitive macros.
Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.