Описание
A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.
Уязвимые конфигурации
Конфигурация 1Версия до 13.0.52 (включая)
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00039
Низкий
8.8 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.8
github
около 2 месяцев назад
A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.
EPSS
Процентиль: 12%
0.00039
Низкий
8.8 High
CVSS3
Дефекты
CWE-89