vendor:
Kentico CMS
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Kentico CMS
Affected Version From: Kentico CMS 5.5R2.23
Affected Version To: Kentico CMS (other versions may also be affected)
Patch Exists: NO
Related CWE:
CPE: a:kentico:kentico_cms:5.5r2.23
Platforms Tested:
2020
Cross-Site Scripting Vulnerability in Kentico CMS
The vulnerability exists due to insufficient sanitization of user-supplied data in Kentico CMS. An attacker can exploit this issue by injecting arbitrary script code in the browser of a victim user, potentially leading to the theft of authentication credentials and other attacks.
Mitigation:
Apply the latest security patches or updates provided by the vendor. Additionally, input validation and output encoding should be implemented to prevent XSS attacks.