Description

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

INFO

Published Date :

2025-03-24T18:16:04.022Z

Last Modified :

2026-02-26T19:09:16.392Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2746 vulnerability.

Vendors Products
Kentico
  • Xperience

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact