Home/CVEs/CVE-2019-10068/

CVE-2019-10068 - Kentico Xperience Deserialization of Untrusted Data Vulnerability

Project:Kentico

Product:Xperience

Date Added:2022-03-25Due Date:2022-04-15

Vulnerability Name

Kentico Xperience Deserialization of Untrusted Data Vulnerability

Description

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-10068