CVE-2025-2794

An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, leading to a Denial-of-Service condition. This issue affects Xperience: through 13.0.180.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*

History

22 Sep 2025, 18:45

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de reflexión insegura en Kentico Xperience permite que un atacante no autenticado finalice el proceso actual, lo que genera una condición de denegación de servicio. Este problema afecta a Xperience hasta la versión 13.0.180.
CPE cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
First Time Kentico xperience
Kentico
References () https://devnet.kentico.com/download/hotfixes - () https://devnet.kentico.com/download/hotfixes - Product

31 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 17:15

Updated : 2025-09-22 18:45


NVD link : CVE-2025-2794

Mitre link : CVE-2025-2794

CVE.ORG link : CVE-2025-2794


JSON object : View

Products Affected

kentico

  • xperience
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')