Description
Kentico CMS is an ASP.NET web content management system.
The Staging API is used to replicate data between production and development systems. If an attacker has valid credentials for the API, they can get full access to the system.
Remediation
Restrict access to the Staging API
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6105)
Squid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-12529)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-15005)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5097)
WordPress Plugin Welcart e-Commerce Information Disclosure (2.2.7)