CVE Vulnerabilities

CVE-2017-17736

Direct Request ('Forced Browsing')

Published: Mar 23, 2018 | Modified: Dec 19, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Xperience Kentico 9.0 (including) 9.0.51 (excluding)
Xperience Kentico 10.0 (including) 10.0.48 (excluding)

Potential Mitigations

References