An authentication bypass vulnerability in Kentico...
Critical severity
Unreviewed
Published
Mar 24, 2025
to the GitHub Advisory Database
•
Updated Mar 24, 2025
Description
Published by the National Vulnerability Database
Mar 24, 2025
Published to the GitHub Advisory Database
Mar 24, 2025
Last updated
Mar 24, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
References