Vulnerability Description
An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kentico | Xperience | <= 12.0.60 |
Related Weaknesses (CWE)
References
- https://devnet.kentico.com/download/hotfixesProduct
- https://www.vulncheck.com/advisories/kentico-xperience-administrator-access-contThird Party Advisory
FAQ
What is CVE-2020-36890?
CVE-2020-36890 is a vulnerability with a CVSS score of 7.2 (HIGH). An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise globa...
How severe is CVE-2020-36890?
CVE-2020-36890 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36890?
Check the references section above for vendor advisories and patch information. Affected products include: Kentico Xperience.