Description
A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
James Taylor | Cantarus
References
devnet.kentico.com/download/hotfixes (Kentico DevNet Hotfixes)
www.vulncheck.com/...-administration-interface-reflected-xss (VulnCheck Advisory: Kentico Xperience <= 13.0.120 Administration Interface Reflected XSS)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.