A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers. | |
| Title | Kentico Xperience <= 12.0.49 File Upload Stored XSS | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-18T19:53:26.107Z
Updated: 2025-12-18T21:48:14.482Z
Reserved: 2025-12-09T11:05:19.896Z
Link: CVE-2020-36891
Updated: 2025-12-18T21:09:00.634Z
Status : Received
Published: 2025-12-18T20:15:49.490
Modified: 2025-12-18T20:15:49.490
Link: CVE-2020-36891
No data.