Collected research
Bypassing Authentication Like It's The '90s: Pre-Auth RCE Chain(s) in Kentico Xperience CMS
Follows SOAP UsernameToken handling through a custom password callback and attacker-selected authentication modes. An empty-secret digest and a later omitted-password variant bypass Kentico staging authentication under different conditions, after which media-file path traversal provides the write primitive used in the execution chain.
Record
- Researcher
- Piotr Bazydlo
- Published by
- watchTowr
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Piotr Bazydlo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .