Cross-Site Scripting Vulnerability in Kentico CMS by Kentico Software
CVE-2018-6842

5.4MEDIUM

Key Information:

Vendor

Kentico

Vendor
CVE Published:
19 March 2018

What is CVE-2018-6842?

Kentico CMS versions 10 and 11 are susceptible to a Cross-Site Scripting vulnerability that arises from the improper handling of crafted URLs, leading to the potential for unauthorized access to system pages. This flaw can enable attackers to execute arbitrary scripts in the context of an affected user's session, posing significant security risks to web applications utilizing this platform.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-6842 : Cross-Site Scripting Vulnerability in Kentico CMS by Kentico Software