---
title: Security advisory 2025-01-09
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

## Broken access control between contact groups and recipient lists

**CVSS**: 5.3\
**Affected versions**: 24.0.0 - 30.0.1\
**Category**: IDOR

### Summary

An authorization issue allowed the modification of [contact group](https://docs.kentico.com/documentation/business-users/digital-marketing/contact-groups.md) objects from the _Recipient lists_ application and [recipient list](https://docs.kentico.com/documentation/business-users/digital-marketing/emails/send-regular-emails-to-subscribers.md) objects from the _Contact groups_ application, even if the user didn’t have permissions for the related application. After applying the fix, permissions are validated correctly, and only objects belonging to the given application can be modified.

### How to fix

Update to the latest version. See [Update Xperience by Kentico projects](https://docs.kentico.com/documentation/developers-and-admins/installation/update-xperience-by-kentico-projects.md) for detailed instructions.
