Description
Kentico CMS is an ASP.NET web content management system.
Kentico CMS API uses .NET deserialization of user-supplied data. Arbitrary object deserialization is inherently unsafe, and should never be performed on untrusted data.
Remediation
Upgrade to the latest version of Kentico CMS
References
Related Vulnerabilities
Oracle ADF Faces 'Miracle' RCE (CVE-2022-21445)
Oracle Business Intelligence ReportTemplateService XXE CVE-2019-2616
WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.14)
WordPress Plugin Download Manager PHAR Deserialization (3.2.49)
Apache Solr Deserialization of untrusted data via jmx.serviceUrl