An authentication bypass vulnerability has been identified in Kentico Xperience CMS versions prior to 13.0.178. The vulnerability stems from a third-party library used by the product, allowing attackers to bypass the staging authentication mechanism. This issue affects only instances with staging enabled. Importantly, this vulnerability involves a distinct attack vector from the one addressed in hotfix 13.0.173. Administrators are advised to apply hotfix 13.0.178. For instances not using staging, an additional protective measure is to restrict access to the staging endpoint /CMSPages/Staging/SyncServer.asmx. This can be done by editing the node in the /CMS/CMSPages/Web.config file. To fully block access, set the authorization setting to . The findings are detailed in this post.
References:

