Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8010 | An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Kentico Xperience Staging media files upload authenticated remote code execution | Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE |
Thu, 16 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* |
Mon, 24 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Mon, 24 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178. | |
| Title | Kentico Xperience Staging media files upload authenticated remote code execution | |
| Weaknesses | CWE-22 CWE-434 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-04T22:18:54.073Z
Reserved: 2025-03-24T16:39:22.986Z
Link: CVE-2025-2749
Updated: 2025-03-24T18:44:16.090Z
Status : Modified
Published: 2025-03-24T19:15:52.400
Modified: 2025-11-04T23:15:34.703
Link: CVE-2025-2749
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:07Z
EUVD