← Back

CVE-2017-17736

Published: Mar 23, 2018Modified: Dec 19, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

Affected (2)

Products: Kentico: Xperience
1 product
Xperience
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Kentico
From 10.0 to 10.0.48
From 9.0 to 9.0.51

References (2)

Timeline

No history available yet.