CVE-2017-17736

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
23/03/2018
Last modified:
03/10/2019

Description

Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kentico:kentico_cms:*:*:*:*:*:*:*:* 9.0 (including) 9.0.51 (excluding)
cpe:2.3:a:kentico:kentico_cms:*:*:*:*:*:*:*:* 10.0 (including) 10.0.48 (excluding)