vendor:
Kentico - Content Management System (eCommerce Software)
by:
Vulnerability Laboratory
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Kentico - Content Management System (eCommerce Software)
Affected Version From: 9.0
Affected Version To: 11.0
Patch Exists: YES
Related CWE: CVE-2018-5282
CPE: a:kentico_software:kentico
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Kentico CMS v11.0 – Stack Buffer Overflow Vulnerability
A stack buffer overflow vulnerability has been discovered in the official Kentico v9.0, v10.0 & v11.0 content management system software. The vulnerability allows local attackers to compromise the software service to execute system specific attacks. The vulnerability is located in the `/CMSModules/AdminControls/Controls/Selectors/UserSelector.ascx.cs` file. Local attackers are able to inject own malicious script codes to compromise the software service. The request method to inject is POST and the attack vector is located on the application-side of the service.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable user input fields. Restrict the input and disallow special chars and encode the output.