CRITICAL

CVE-2025-2747

Kentico Xperience 2025-03-24 CVSS v3.1
CVSS
9.8
KEV

Description

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.

Summary dbcve.org

Kentico Xperience versions through 13.0.178 contain an authentication bypass vulnerability in the Staging Sync Server component. The vulnerability stems from improper password handling for servers configured with the 'None' type, allowing unauthenticated attackers to bypass authentication and gain control over administrative objects.

Mitigation

Upgrade Kentico Xperience to version 13.0.179 or later. Alternatively, review and reconfigure staging server settings to avoid the 'None' type definition, and ensure staging servers use proper authentication mechanisms.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-288

EPSS Score

92.49%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE