CVE-2025-32369

Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*

History

08 Apr 2025, 17:27

Type Values Removed Values Added
First Time Kentico
Kentico xperience
CPE cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
References () https://devnet.kentico.com/download/hotfixes - () https://devnet.kentico.com/download/hotfixes - Release Notes
References () https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748/ - () https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748/ - Exploit, Third Party Advisory

07 Apr 2025, 14:17

Type Values Removed Values Added
References
  • () https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748/ -
Summary
  • (es) Kentico Xperience anterior a 13.0.181 permite a los usuarios autenticados distribuir contenido malicioso (para XSS almacenado) a través de ciertas interacciones con la función de carga de archivos de la librería multimedia.

06 Apr 2025, 07:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4

06 Apr 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-06 06:15

Updated : 2025-04-08 17:27


NVD link : CVE-2025-32369

Mitre link : CVE-2025-32369

CVE.ORG link : CVE-2025-32369


JSON object : View

Products Affected

kentico

  • xperience
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')