CVE advisoryKnown Exploit
CVE-2019-10068
Kentico Xperience: Unauthenticated Remote Code Execution Vulnerability
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in Kentico Xperience's staging service allows unauthenticated remote code execution. Attackers can exploit a failure to validate security headers to bypass authentication and deserialize malicious input, potentially compromising hosted systems and data. This poses a significant risk to affected organiza