Web Hack List

Collected research

Bypassing Authentication Like It's The '90s: Pre-Auth RCE Chain(s) in Kentico Xperience CMS

Follows SOAP UsernameToken handling through a custom password callback and attacker-selected authentication modes. An empty-secret digest and a later omitted-password variant bypass Kentico staging authentication under different conditions, after which media-file path traversal provides the write primitive used in the execution chain.

Record

Researcher
Piotr Bazydlo
Published by
watchTowr
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Bazydlo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .