peter bassill · operator
$ cve CVE-2018-5282 JSON

CVE-2018-5282 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 1.5% (pctl 74)

Patch early

A public exploit exists.

Description

Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disputes this issue because neither a buffer overflow nor a crash can be reproduced; also, reading XML documents is implemented exclusively with managed code within the Microsoft .NET Framework

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.55% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2018-01-08
Last modified2026-06-17

Affected (1)

VendorProduct
kenticoxperience

Public exploits

SourceTitleDate
exploit-dbKentico CMS 11.0 - Buffer Overflow2018-01-12

References

→ the Explorer  ·  watch your stack  ·  NVD