Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-04-15T23:52:42
Updated: 2024-08-03T06:17:54.687Z
Reserved: 2022-04-15T00:00:00
Link: CVE-2022-29287
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-04-16T00:15:09.533
Modified: 2024-11-21T06:58:52.190
Link: CVE-2022-29287
Redhat
No data.