Metrics
Affected Vendors & Products
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Kentico Xperience Staging media files upload authenticated remote code execution | Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE |
Thu, 16 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* |
Mon, 24 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Mon, 24 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178. | |
| Title | Kentico Xperience Staging media files upload authenticated remote code execution | |
| Weaknesses | CWE-22 CWE-434 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-03-24T18:18:07.228Z
Updated: 2025-11-04T22:18:54.073Z
Reserved: 2025-03-24T16:39:22.986Z
Link: CVE-2025-2749
Updated: 2025-03-24T18:44:16.090Z
Status : Modified
Published: 2025-03-24T19:15:52.400
Modified: 2025-11-04T23:15:34.703
Link: CVE-2025-2749
No data.