Reflected Cross-Site Scripting Vulnerability in Kentico Xperience
CVE-2022-50681
5.1MEDIUM
What is CVE-2022-50681?
A reflected cross-site scripting (XSS) vulnerability in Kentico Xperience can be exploited by attackers through the Rich text editor component. By injecting malicious scripts via administration input fields, an attacker could execute arbitrary code in the context of users' browsers. This vulnerability emphasizes the importance of securing input fields within web applications to prevent script injection and protect user data.
Affected Version(s)
Xperience 0 <= 13.0.88
