Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 13.0.79
A CRLF injection vulnerability has been identified in Kentico Xperience versions through 13.0.79. This vulnerability allows attackers to manipulate URL query string redirects due to improper encoding in the routing engine. Such manipulation could lead to header injection and potentially facilitate further attacks on the web application.
Exploitation of this vulnerability could allow for CRLF injection, leading to header injection and potentially further web application attacks.
Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.