CVE-2018-5282 | Kentico CMS 8.x/9.x/10.x/11.0 SilentInstall XML Document SqlName/SqlPswd/Database/UserName/Password memory corruption (EDB-43547)
A vulnerability, which was classified as critical, has been found in Kentico CMS 8.x/9.x/10.x/11.0. This impacts an unknown function of the component SilentInstall XML Document Handler. Performing manipulation of the argument SqlName/SqlPswd/Database/UserName/Password as part of XML Document results in memory corruption.
This vulnerability was named CVE-2018-5282. The attack needs to be approached locally. In addition, an exploit is available.
The actual existence of this vulnerability is currently in question.