CVE-2019-25229: Kentico Xperience <= 12.0.29 MVC Forms Unrestricted File Upload
An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25229?
CVE-2019-25229 is considered a high-severity vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2019-25229?
To remediate CVE-2019-25229, ensure you are using a patched version of Kentico Xperience above version 12.0.29.
Who is affected by CVE-2019-25229?
CVE-2019-25229 affects authenticated users of Kentico Xperience with 'Read data' permissions.
What type of attack is possible with CVE-2019-25229?
CVE-2019-25229 allows attackers to upload potentially malicious files, which can lead to further exploitation.
Can CVE-2019-25229 be exploited remotely?
Yes, CVE-2019-25229 can be exploited remotely by authenticated users with the appropriate permissions.