CVE-2019-12102: Critical severity Kentico Kentico vulnerability
DISPUTED Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabsmedia.aspx URI. NOTE: The vendor disputes the report because the researcher did not configure the media library permissions correctly. The vendor states that by default all users can read/modify/upload files, and it’s up to the administrator to decide who should have access to the media library and set the permissions accordingly. See the vendor documentation in the references for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12102?
The severity level of CVE-2019-12102 is disputed by the vendor, but it allows for potential unauthorized file uploads.
How do I fix CVE-2019-12102?
Fixing CVE-2019-12102 typically involves properly configuring media library permissions in Kentico.
What versions are affected by CVE-2019-12102?
CVE-2019-12102 affects Kentico versions 11.0.0 through 12.0.
What types of attacks can CVE-2019-12102 facilitate?
CVE-2019-12102 can facilitate unauthorized file uploads and exploration by attackers.
Is there any vendor response to CVE-2019-12102?
Yes, the vendor disputes the report as it claims the researcher did not configure the media library permissions correctly.