Missing Critical Step in Authentication Affecting kentico.xperience.libraries package, versions [,13.0.173)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.12% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-KENTICOXPERIENCELIBRARIES-9689933
  • published14 Apr 2025
  • disclosed24 Mar 2025
  • creditPiotr Bazydlo

Introduced: 24 Mar 2025

NewCVE-2025-2746  (opens in a new tab)
CWE-304  (opens in a new tab)

How to fix?

Upgrade Kentico.Xperience.Libraries to version 13.0.173 or higher.

Overview

Kentico.Xperience.Libraries is a package for libraries and applications that use Kentico Xperience API.

Affected versions of this package are vulnerable to Missing Critical Step in Authentication due to improper handling of empty SHA1 usernames in digest authentication, when the Staging Sync Server is enabled (which it is not by default). An attacker can gain unauthorized access and control over administrative objects by sending malicious requests with empty usernames, which are handled by a Microsoft.Web.Services3 implementation with insufficient verification.

CVSS Base Scores

version 4.0
version 3.1