PT-2025-12671 · Kentico · Kentico Xperience

Piotr Bazydlo

·

Published

2025-03-24

·

Updated

2026-04-22

·

CVE-2025-2749

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kentico Xperience versions prior to 13.0.179
Description An authenticated remote code execution issue allows authenticated users of the Staging Sync Server to upload arbitrary data to path relative locations. This leads to path traversal and arbitrary file upload, enabling the upload of content that can be executed on the server side, resulting in remote code execution. This issue has been actively exploited in real-world incidents.
Recommendations Update to a version newer than 13.0.178.

Exploit

Fix

RCE

Path traversal

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-2749

Affected Products

Kentico Xperience