Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 13.0.162
A stored cross-site scripting vulnerability has been identified in Kentico Xperience versions through 13.0.162. This vulnerability allows attackers to inject malicious scripts via the rich text editor component used in page and form builders. Exploitation involves entering harmful URIs, which could enable the execution of malicious scripts in the browsers of users.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.