vendor:
Kentico Xperience
by:
Alex Messham
6.1
CVSS
HIGH
Cross Site Scripting (XSS)
79
CWE
Product Name: Kentico Xperience
Affected Version From: Kentico Xperience before 13.0.178
Affected Version To: Kentico Xperience 13.0.178
Patch Exists: YES
Related CWE: CVE-2025-32370
CPE: a:kentico:kentico_xperience:13.0.178
Platforms Tested:
2025
Kentico Xperience 13.0.178 – Cross Site Scripting (XSS)
The exploit involves uploading a ZIP file containing a malicious SVG file to achieve Cross Site Scripting (XSS) on Kentico Xperience version before 13.0.178. The malicious SVG file triggers an alert box when executed.
Mitigation:
To mitigate this vulnerability, it is recommended to update Kentico Xperience to version 13.0.178 or later. Additionally, input validation should be implemented to prevent malicious file uploads.