CVE-2025-2794: Kentico Xperience <= 13.0.180 Unsafe Reflection
Published Mar 31, 2025
·Updated
An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, leading to a Denial-of-Service condition.
This issue affects Xperience: through 13.0.180.
Affected Software
2 affected components
Kentico Xperience<=13.0.180
Kentico Xperience<=13.0.180
Event History
Mar 31, 2025
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 23, 57823
Event
via NVD·09:09 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2794?
CVE-2025-2794 is classified as a high-severity vulnerability due to its potential to cause Denial-of-Service conditions.
2
How do I fix CVE-2025-2794?
To fix CVE-2025-2794, upgrade to a version of Kentico Xperience that is newer than 13.0.180.
3
Who is affected by CVE-2025-2794?
CVE-2025-2794 affects all users of Kentico Xperience versions up to and including 13.0.180.
4
What type of attack does CVE-2025-2794 enable?
CVE-2025-2794 enables unauthenticated attackers to terminate the current process, resulting in a Denial-of-Service.
5
Is user authentication required to exploit CVE-2025-2794?
No, CVE-2025-2794 can be exploited by unauthenticated attackers, making it more critical.