Description
Kentico CMS is an ASP.NET web content management system.
The Staging API is used to replicate data between production and development systems. If an attacker has valid credentials for the API, they can get full access to the system.
Remediation
Restrict access to the Staging API
References
Related Vulnerabilities
Verb tampering via misconfigured security constraint
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2038)
Unrestricted access to ImageResizer Diagnotics plugin
JBoss HttpAdaptor JMXInvokerServlet
WordPress Plugin NextGEN Gallery-WordPress Gallery Information Disclosure (1.9.11)