PT-2018-6559 · Kentico · Kentico

CVE-2017-17736

·

Publicado

2018-03-23

·

Atualizado

2025-12-19

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Kentico versions 9.0 through 9.0.50 Kentico versions 10.0 through 10.0.47
Description: The issue allows remote attackers to obtain Global Administrator access. This can be achieved by visiting the "CMSInstall/install.aspx" endpoint and then navigating to the CMS Administration Dashboard.
Recommendations: For Kentico versions 9.0 through 9.0.50, update to version 9.0.51 or later. For Kentico versions 10.0 through 10.0.47, update to version 10.0.48 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17736

Produtos afetados

Kentico