CVE-2025-2746 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames i…
Critical KEV CVSS: 9.8

CVE-2025-2746

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
Vendor
Kentico
Product
Xperience
CWE
CWE-288
Yayın Tarihi
2025-03-24 19:15:51
Güncelleme
2025-11-06 13:58:06
Source Identifier
disclosure@vulncheck.com
KEV Date Added
2025-10-20

Kategoriler

Referanslar