Kentico CMS 7.0.75 - User Information Disclosure
PHP:
This vulnerability is an unprotected page on the site where you can view
all current users and usernames.
To find out if a Kentico CMS is vulnerable go to
http://site.com/CMSModules/Messaging/CMSPages/PublicMessageUserSelector.aspx
assuming that the Kentico CMS was installed to the root folder in the
server.
I have already notified the authors and security team for Kentico CMS, in
their response they claimed they would issue a patch on 02-21-2014.
# Â 0day.today [2017-11-15] Â #

