QID 379490

Date Published: 2024-04-03

QID 379490: Kentico Insufficient Information Vulnerability

In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.

Affected Versions
Kentico before 13.0.66

QID Detection Logic 9Authenticated)
This qid checks for vulnerable version of Kentico

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to here to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 379490

    Software Advisories
    Advisory ID Software Component Link
    Kentico Windows URL Logo Kentico before 13.0.66