CVE-2018-5282

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
08/01/2018
Last modified:
19/12/2025

Description

Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disputes this issue because neither a buffer overflow nor a crash can be reproduced; also, reading XML documents is implemented exclusively with managed code within the Microsoft .NET Framework

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* 9.0 (including) 11.0 (including)