Логотип exploitDog
bind:CVE-2022-50685
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-50685

Количество 2

Количество 2

nvd логотип

CVE-2022-50685

около 2 месяцев назад

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j96v-c89v-53cv

около 2 месяцев назад

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-50685

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-j96v-c89v-53cv

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

CVSS3: 4.6
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу