Authentication Bypass by Primary Weakness Affecting kentico.xperience.libraries package, versions [,13.0.178)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.12% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-KENTICOXPERIENCELIBRARIES-9689936
  • published14 Apr 2025
  • disclosed24 Mar 2025
  • creditPiotr Bazydlo

Introduced: 24 Mar 2025

NewCVE-2025-2747  (opens in a new tab)
CWE-305  (opens in a new tab)

How to fix?

Upgrade Kentico.Xperience.Libraries to version 13.0.178 or higher.

Overview

Kentico.Xperience.Libraries is a package for libraries and applications that use Kentico Xperience API.

Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness when the Staging Sync Server is enabled (which it is not by default). An attacker can gain unauthorized access and control over administrative objects by sending malicious requests with a valid username but no password, which are handled by a Microsoft.Web.Services3 implementation with insufficient verification.

Note: As of version 13.0.173 this vulnerability can only be exploited with a valid username whereas prior to that release it was exploitable without providing any username at all.

CVSS Base Scores

version 4.0
version 3.1