A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session security and authentication state.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XKentico Xperience
APPKentico≤ 13.0.164
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2025-2747CRITICAL9.8⚠ KEVPL ✓same product
Kentico Xperience — Authentication Bypass w komponencie Staging Sync Server
CVE-2025-2746CRITICAL9.8⚠ KEVPL ✓same product
Kentico Xperience – pominięcie uwierzytelnienia w Staging Sync Server
CVE-2019-10068CRITICAL9.8⚠ KEVPL ✓same product
Kentico CMS – nieuwierzytelnione RCE przez podatną deserializację .NET
CVE-2019-12102CRITICAL9.1PL ✓same product
Kentico CMS — nieautoryzowany upload i przeglądanie plików w media library
CVE-2017-17736CRITICAL9.8PL ✓same product
Kentico CMS — ominięcie kontroli dostępu do panelu administratora