The Kentico Xperience application does not fully validate...
Moderate severity
Unreviewed
Published
Mar 24, 2025
to the GitHub Advisory Database
•
Updated Mar 24, 2025
Description
Published by the National Vulnerability Database
Mar 24, 2025
Published to the GitHub Advisory Database
Mar 24, 2025
Last updated
Mar 24, 2025
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.
References