Kentico Xperience 13 CMS - Staging Service 身份验证绕过检测
python3 watchTowr-vs-kentico-xperience13-AuthBypass-wt-2025-0006.py -H http://labcms
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__/
\/ \/ \/
watchTowr-vs-kentico-xperience13-AuthBypass-wt-2025-0006.py
(*) WT-2025-0006: Kentico Xperience 13 CMS - Staging Service Authentication Bypass Check
- Piotr Bazydlo (@chudyPB) of watchTowr
CVEs: TBD
[+] Verifying Authentication Bypass in Staging API
[+] VULNERABLE: Authentication Bypassed!
该脚本尝试绕过 Kentico Xperience 13 CMS Staging Service 的身份验证。它发送一个 POST 请求并分析 API 响应。
未对其他 Kentico Xperience 版本进行测试(例如 Kentico Xperience 12)。
仅对启用了 Staging Service 并使用用户名/密码身份验证的目标有效
如需获取最新安全研究,请关注 watchTowr 实验室团队