Vulnerability Description
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kentico | Xperience | >= 9.0, <= 11.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/541790/100/0/threadedExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/541790/100/0/threadedExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-7046?
CVE-2018-7046 is a vulnerability with a CVSS score of 7.2 (HIGH). Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in...
How severe is CVE-2018-7046?
CVE-2018-7046 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7046?
Check the references section above for vendor advisories and patch information. Affected products include: Kentico Xperience.