CVE-2019-12102
Last modified
CVE-2019-12102 is a vulnerability of currently unknown severity. Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs_media.aspx URI. NOTE: The vendor disputes the report because the researcher did not configure the media library permissions correctly. EPSS estimates a 2.16% chance of exploitation in the next 30 days.
Description
Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs_media.aspx URI. NOTE: The vendor disputes the report because the researcher did not configure the media library permissions correctly. The vendor states that by default all users can read/modify/upload files, and it’s up to the administrator to decide who should have access to the media library and set the permissions accordingly. See the vendor documentation in the references for more information
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kentico | Xperience | >= 11.0.0, <= 12.0 |
References
- https://devnet.kentico.com/download/hotfixesVendor Advisory
- https://docs.kentico.com/k12/release-notes-kentico-12Release Notes, Vendor Advisory
- https://devnet.kentico.com/download/hotfixesVendor Advisory
- https://docs.kentico.com/k12/release-notes-kentico-12Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12102?
How severe is CVE-2019-12102?
How do I fix CVE-2019-12102?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-12095Horde Trean, as used in Horde Groupware Webmail Edition thro…8.8
- CVE-2019-12097Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of …
- CVE-2019-12098In the client side of Heimdal before 7.6.0, failure to verif…7.4
- CVE-2019-12099In PHP-Fusion 9.03.00, edit_profile.php allows remote authen…
- CVE-2019-1210Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-12101coap_decode_option in coap.c in LibNyoci 0.07.00rc1 mishandl…
- CVE-2019-12103The web-based configuration interface of the TP-Link M7350 V…
- CVE-2019-12104The web-based configuration interface of the TP-Link M7350 V…
- CVE-2019-12105In Supervisor through 4.0.2, an unauthenticated user can rea…8.2
- CVE-2019-12106The updateDevice function in minissdpd.c in MiniUPnP MiniSSD…
- CVE-2019-12107The upnp_event_prepare function in upnpevents.c in MiniUPnP …
- CVE-2019-12108A Denial Of Service vulnerability in MiniUPnP MiniUPnPd thro…
Are you affected by CVE-2019-12102?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
