CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-2746

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-03-24
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

Affected Platforms (CPE)

📦
Kentico

Xperience

<= 13.0.172

References & Advisories

相關漏洞威脅