CVE-2025-2749 IBM QRadar · QRadar

Detect Kentico Xperience Path Traversal and Arbitrary File Upload (CVE-2025-2749) in IBM QRadar

Detects exploitation of CVE-2025-2749, a path traversal and unrestricted file upload vulnerability in Kentico Xperience CMS. Attackers can traverse directory boundaries to write arbitrary files — including web shells — to locations outside the intended upload path, enabling remote code execution on the hosting server. This CVE is listed in the CISA Known Exploited Vulnerabilities catalog.

MITRE ATT&CK

Tactic
Initial Access Execution Persistence

QRadar Detection Query

IBM QRadar (QRadar)
sql
SELECT
  DATEFORMAT(starttime, 'YYYY-MM-dd HH:mm:ss') AS event_time,
  sourceip,
  "URL" AS request_url,
  "Method" AS http_method,
  "Response Code" AS http_status,
  "User Agent" AS user_agent,
  LOGSOURCENAME(logsourceid) AS log_source
FROM events
WHERE LOGSOURCETYPENAME(devicetype) IN ('Microsoft IIS', 'Apache HTTP Server')
  AND (LOWER("URL") LIKE '%/kentico/%'
    OR LOWER("URL") LIKE '%/cmspages/%'
    OR LOWER("URL") LIKE '%/cmsformcontrols/%'
    OR LOWER("URL") LIKE '%/uploadfile/%')
  AND (LOWER("URL") LIKE '%../%'
    OR LOWER("URL") LIKE '%..\\%'
    OR LOWER("URL") LIKE '%..%2f%'
    OR LOWER("URL") LIKE '%..%5c%'
    OR LOWER("URL") LIKE '%%252e%2e%')
  AND LOGSOURCETIME > NOW() - 1 HOURS
ORDER BY starttime DESC
LIMIT 500
critical severity medium confidence

Queries QRadar for IIS and web server log events matching Kentico Xperience upload paths combined with path traversal indicators, surfacing potential CVE-2025-2749 exploitation attempts.

Data Sources

Microsoft IIS DSMApache HTTP Server DSM

Required Tables

events

False Positives & Tuning

  • Automated security scanners generating path traversal payloads during authorized assessments
  • CMS import/export tools that reference relative paths in uploaded archives
  • Encoded characters in international content filenames misidentified as traversal sequences

Other platforms for CVE-2025-2749


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Kentico Path Traversal Upload Simulation

    Expected signal: IIS access log records a POST to /kentico/cmsformcontrols/uploader.ashx with a filename parameter containing '../..' sequences; file creation event may appear in Windows Security log under w3wp.exe

  2. Test 2Encoded Path Traversal Bypass Attempt

    Expected signal: IIS log shows double-encoded percent sequences in the request URL; WAF logs may show allowed request if only basic traversal patterns are blocked

  3. Test 3Web Shell Execution Post-Exploit Simulation

    Expected signal: Windows Security Event ID 4663 fires for file creation under w3wp.exe; DeviceFileEvents in Defender shows .aspx file written by w3wp.exe; subsequent HTTP GET to the shell path appears in IIS logs

Last updated: 2026-06-19 Research depth: standard
References (2)

Unlock Pro Content

Get the full detection package for CVE-2025-2749 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections