Description Kentico CMS up to 9.0.50/10.0.47 CMS Administration Dashboard CMSInstall/install.aspx 访问控制漏洞
References https://nvd.nist.gov/vuln/detail/CVE-2017-17736 https://www.tenable.com/plugins/was/98994 https://www.cvedetails.com/cve/CVE-2017-17736/ https://avd.aliyun.com/detail?id=AVD-2017-17736 https://www.cve.org/CVERecord?id=CVE-2017-17736 https://cve.circl.lu/vuln/cve-2017-17736 https://feedly.com/cve/vendors/kentico
Related VulnerabilitiesPoCCVE-2021-42392: H2 Database Console - JNDI Injection RCEPoCCVE-2026-55549: Yamcs <=5.8.6 - Cross-Site ScriptingPoCCVE-2026-69085: SiYuan <=3.7.2 - SQL InjectionPoCCVE-2026-9103: Langflow OSS - Superuser Token IssuancePoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File ReadPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-19632: TranslatePress <= 3.3.1 - Unauthenticated Account TakeoverPoCCVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp ProxyPoCCVE-2026-29962: HSC MailInspector - Local File InclusionPoCCVE-2026-29963: HSC MailInspector - Unauthenticated Arbitrary File ReadPoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication Bypass