A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session security and authentication state.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session security and authentication state. | |
| Title | Kentico Xperience <= 13.0.164 Cookie Security Configuration | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-614 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T21:19:17.630Z
Reserved: 2025-12-17T16:51:11.809Z
Link: CVE-2024-58317
Updated: 2025-12-18T21:17:46.923Z
Status : Received
Published: 2025-12-18T20:15:53.473
Modified: 2025-12-18T20:15:53.473
Link: CVE-2024-58317
No data.
OpenCVE Enrichment
No data.