Anastasios Stasinopoulos from Obrela LABS team discovered a critical risk vulnerability that affects Kentico CMS, a popular ASP.NET web content management system that is used to build websites, online stores and Web 2.0 community sites.
More specifically, Kentico CMS 5.5 R2 build 5.5.3996 was found vulnerable to SQL injection attacks on a specific parameter, allowing a potential attacker – without requiring authentication – to interact with the backend Microsoft SQL server database.
Successful exploitation of this vulnerability allows unauthorized access/modification/deletion of the stored data in the backend database and if specific conditions are met can be also leveraged to complete compromise of the underlying operating system that hosts Kentico.
The software vendor has been informed by Obrela LABS prior to public disclosure of the vulnerability which was registered afterwards with a CVE record: CVE-2021-27581 .
According to software vendor response it is advised to update Kentico CMS to the latest version that is not vulnerable to this security flaw.
The vulnerability was exploited using the sqlmap tool:
Discovery and public disclosure timeline