Metrics
Affected Vendors & Products
Mon, 24 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
ssvc
|
Mon, 24 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 24 Mar 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178. | |
Title | Kentico Xperience Staging media files upload authenticated remote code execution | |
Weaknesses | CWE-22 CWE-434 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-03-24T18:18:07.228Z
Updated: 2025-03-24T19:16:31.029Z
Reserved: 2025-03-24T16:39:22.986Z
Link: CVE-2025-2749

Updated: 2025-03-24T18:44:16.090Z

Status : Received
Published: 2025-03-24T19:15:52.400
Modified: 2025-03-24T19:15:52.400
Link: CVE-2025-2749

No data.