Hoşgeldin Misafir

Kentico CMS 7.0.75 - User Information Disclosure

|^KahiN^|

24 Eyl 2020
414 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kentico CMS 7.0.75 - User Information Disclosure

PHP:
This vulnerability is an unprotected page on the site where you can view
all current users and usernames.
To find out if a Kentico CMS is vulnerable go to
 
http://site.com/CMSModules/Messaging/CMSPages/PublicMessageUserSelector.aspx
 
assuming that the Kentico CMS was installed to the root folder in the
server.
 
I have already notified the authors and security team for Kentico CMS, in
their response they claimed they would issue a patch on 02-21-2014.

#  0day.today [2017-11-15]  #