Description
A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Kentico Security Team
References
devnet.kentico.com/download/hotfixes (Kentico DevNet Hotfixes)
www.vulncheck.com/...e-online-marketing-macros-sql-injection (VulnCheck Advisory: Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injection)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.