An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, leading to a Denial-of-Service condition.
This issue affects Xperience: through 13.0.180.
References
Link | Resource |
---|---|
https://devnet.kentico.com/download/hotfixes | Product |
Configurations
History
22 Sep 2025, 18:45
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CPE | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
First Time |
Kentico xperience
Kentico |
|
References | () https://devnet.kentico.com/download/hotfixes - Product |
31 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-31 17:15
Updated : 2025-09-22 18:45
NVD link : CVE-2025-2794
Mitre link : CVE-2025-2794
CVE.ORG link : CVE-2025-2794
JSON object : View
Products Affected
kentico
- xperience
CWE
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')