Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 13.0.74
A stored cross-site scripting vulnerability has been identified in Kentico Xperience versions through 13.0.74. This vulnerability allows attackers to inject malicious scripts into form redirect URL configurations. The injected scripts can then execute in the browsers of users who interact with the affected forms, exploiting the unvalidated configuration settings.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users can upgrade to Kentico Xperience version 13.0.75 or later, where this vulnerability has been addressed. Instructions for applying the hotfix can be found on the Kentico Xperience DevNet hotfixes page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.