CVE-2018-7046: OS Command Injection
DISPUTED Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7046?
CVE-2018-7046 is classified as a high severity vulnerability allowing arbitrary code execution.
How do I fix CVE-2018-7046?
To fix CVE-2018-7046, update Kentico CMS to a version later than 11.0.
Who is affected by CVE-2018-7046?
CVE-2018-7046 affects remote authenticated users of Kentico CMS versions 9.0 to 11.0.
What can attackers do with CVE-2018-7046?
Attackers can execute arbitrary operating system commands on the server due to this vulnerability.
Is CVE-2018-7046 a known vulnerability?
Yes, CVE-2018-7046 is a known vulnerability that has been publicly reported and documented.