Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 are susceptible to a privilege escalation attack. An attacker can obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
id: CVE-2017-17736
info:
name: Kentico - Installer Privilege Escalation
author: shiar
severit
...