漏洞描述 Kentico Xperience13 是一款功能强大的内容管理系统(CMS),广泛应用于企业网站和数字体验管理。该系统存在文件读取漏洞(CVE-2025-0011),攻击者可以利用该漏洞绕过权限验证,读取系统中的敏感文件,从而导致信息泄露和潜在的安全风险。
相关漏洞推荐 POCCVE-2025-2748: Kentico Xperience CMS - Unauthenticated Stored XSS POCCVE-2025-2748: Kentico Xperience CMS - Unauthenticated Stored XSS POCkentico-13-auth-bypass-wt-2025-0006: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006) POCkentico-13-auth-bypass-wt-2025-0011: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)