Kentico CMS before 13.0.66 has an Insecure Direct Object...
Moderate severity
Unreviewed
Published
Apr 17, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 16, 2022
Published to the GitHub Advisory Database
Apr 17, 2022
Last updated
Jan 27, 2023
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).
References