CVE-2018-6843: SQL Injection
Published Mar 19, 2018
·Updated
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
Affected Software
4 affected components
Kentico Kentico CMS>=10.0<10.0.50
Kentico Kentico CMS>=11.0<11.0.3
Kentico Xperience>=10.0<10.0.50
Kentico Xperience>=11.0<11.0.3
Event History
Mar 19, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6843?
CVE-2018-6843 is classified as a critical vulnerability due to the potential for SQL injection in the Kentico administration interface.
2
How do I fix CVE-2018-6843?
To mitigate CVE-2018-6843, upgrade Kentico CMS to version 10.0.50 or 11.0.3 or later.
3
What versions of Kentico CMS are affected by CVE-2018-6843?
CVE-2018-6843 affects Kentico CMS versions prior to 10.0.50 and 11.0.3.
4
Can CVE-2018-6843 be exploited remotely?
Yes, CVE-2018-6843 can be exploited remotely through the vulnerable administration interface.
5
What are the potential impacts of exploiting CVE-2018-6843?
Exploiting CVE-2018-6843 may allow an attacker to execute arbitrary SQL queries, which could lead to unauthorized access to sensitive data.