Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 12.0.90
A stored cross-site scripting vulnerability has been identified in Kentico Xperience versions through 12.0.90. This vulnerability allows attackers to inject malicious scripts into error messages by using specially crafted object names. When administrators view these error messages in the administration interface, the injected scripts are executed in their browsers.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the error messages.
Users can upgrade to Kentico Xperience version 13.0.198 or later, where this vulnerability has been fixed. Instructions for applying the hotfix are available on the Kentico Xperience documentation site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.