Vulnerability CVE-2019-12102


Published: 2019-05-22

Description:
** DISPUTED ** Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs_media.aspx URI. NOTE: The vendor disputes the report because the researcher did not configure the media library permissions correctly. The vendor states that by default all users can read/modify/upload files, and it?s up to the administrator to decide who should have access to the media library and set the permissions accordingly. See the vendor documentation in the references for more information.

Type:

CWE-20

(Improper Input Validation)

Vendor: Kentico
Product: Kentico 
Version:
12.0
11.0.9
11.0.8
11.0.7
11.0.6
11.0.5
11.0.47
11.0.46
11.0.45
11.0.44
11.0.43
11.0.42
11.0.41
11.0.40
11.0.4
11.0.39
11.0.38
11.0.37
11.0.36
11.0.35
11.0.34
11.0.33
11.0.32
11.0.31
11.0.30
11.0.3
11.0.29
11.0.28
11.0.27
11.0.26
11.0.25
11.0.24
11.0.23
11.0.22
11.0.21
11.0.20
11.0.2
11.0.19
11.0.18
11.0.17
11.0.16
11.0.15
11.0.14
11.0.13
11.0.12
11.0.11
11.0.10
11.0.1
11.0.0

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None

 References:
https://devnet.kentico.com/download/hotfixes
https://docs.kentico.com/k12/configuring-kentico/configuring-the-environment-for-content-editors/configuring-media-libraries/assigning-permissions-to-media-libraries
https://docs.kentico.com/k12/release-notes-kentico-12
https://github.com/Gr4y21/My-CVE-IDs/blob/master/Kentico%20CMS%20Unauthenticated%20File%20Upload%20and%20File%20Exposure

Related CVE
CVE-2019-10068
An issue was discovered in Kentico before 12.0.15. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled ....
CVE-2019-6242
** DISPUTED ** Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor considers this a best-practice violation but not a vulnerability. The vendor plans to fix ...
CVE-2015-7823
Open redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the link parameter.
CVE-2015-7822
Multiple cross-site scripting (XSS) vulnerabilities in Kentico CMS 8.2 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter name to CMSModules/AdminControls/Pages/UIPage.aspx or the (2) CMSBodyClass cookie variable to the...

Copyright 2019, cxsecurity.com

 

Back to Top