Reflected Cross-Site Scripting in Kentico CMS Versions 9 to 11
CVE-2018-7205

4.8MEDIUM

Key Information:

Vendor

Kentico

Vendor
CVE Published:
20 February 2018

What is CVE-2018-7205?

A reflected cross-site scripting vulnerability exists in the Design feature of Kentico CMS versions 9 through 11. This issue allows remote attackers to execute arbitrary JavaScript by manipulating the devicename parameter in a crafted URL. When an authorized user is tricked into clicking on this link, the malicious script can be executed in the context of the user's session, potentially leading to data theft or other unauthorized actions. This vulnerability highlights the need for ensuring input validation and proper sanitization in user inputs, particularly within editing and design functionalities.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-7205 : Reflected Cross-Site Scripting in Kentico CMS Versions 9 to 11