CVE-2017-17736: Critical severity Kentico Kentico CMS vulnerability
Published Mar 23, 2018
·Updated
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
Affected Software
4 affected components
Kentico Kentico CMS>=9.0<9.0.51
Kentico Kentico CMS>=10.0<10.0.48
Kentico Xperience>=9.0<9.0.51
Kentico Xperience>=10.0<10.0.48
Event History
Mar 23, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-17736?
CVE-2017-17736 is considered a critical vulnerability as it allows remote attackers to gain Global Administrator access.
2
How do I fix CVE-2017-17736?
To fix CVE-2017-17736, update Kentico CMS to version 9.0.51 or 10.0.48 or later.
3
Which versions of Kentico CMS are affected by CVE-2017-17736?
CVE-2017-17736 affects Kentico CMS versions prior to 9.0.51 and 10.0.48.
4
Can CVE-2017-17736 be exploited remotely?
Yes, CVE-2017-17736 can be exploited remotely by accessing CMSInstall/install.aspx.
5
What access does an attacker gain from CVE-2017-17736?
An attacker exploiting CVE-2017-17736 can obtain Global Administrator access to the Kentico CMS.