Kentico CMS in version 7 is vulnerable to a Reflected XSS...
Moderate severity
Unreviewed
Published
Jan 2, 2025
to the GitHub Advisory Database
•
Updated Jan 2, 2025
Description
Published by the National Vulnerability Database
Jan 2, 2025
Published to the GitHub Advisory Database
Jan 2, 2025
Last updated
Jan 2, 2025
Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parameter sent to /CMSMessages/AccessDenied.aspx endpoint.
Notably, support for this version of Kentico ended in 2016. Version 8 was tested as well and does not contain this vulnerability.
References