Description
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 19 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kentico xperience
|
|
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico kentico Cms
|
Kentico xperience
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:59:17.691Z
Reserved: 2017-12-18T00:00:00.000Z
Link: CVE-2017-17736
No data.
Status : Modified
Published: 2018-03-23T15:29:00.223
Modified: 2025-12-19T20:56:46.070
Link: CVE-2017-17736
No data.
OpenCVE Enrichment
No data.
Weaknesses