CVE-2025-32370

Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a separate issue not necessarily related to SVG or XSS.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*

History

08 Apr 2025, 18:54

Type Values Removed Values Added
CWE CWE-434
First Time Kentico
Kentico xperience
CPE cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
References () https://devnet.kentico.com/download/hotfixes - () https://devnet.kentico.com/download/hotfixes - Release Notes
References () https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748/ - () https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748/ - Exploit, Third Party Advisory

07 Apr 2025, 14:17

Type Values Removed Values Added
References () https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748/ - () https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748/ -
Summary
  • (es) Kentico Xperience anterior a la versión 13.0.178 tiene un conjunto específico de extensiones de archivo ContentUploader permitidas para cargas no autenticadas. Sin embargo, dado que los archivos .zip se procesan mediante TryZipProviderSafe, existe una funcionalidad adicional para crear archivos con otras extensiones. NOTA: Este problema es independiente y no está necesariamente relacionado con SVG ni XSS.

06 Apr 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-06 07:15

Updated : 2025-04-08 18:54


NVD link : CVE-2025-32370

Mitre link : CVE-2025-32370

CVE.ORG link : CVE-2025-32370


JSON object : View

Products Affected

kentico

  • xperience
CWE
CWE-912

Hidden Functionality

CWE-434

Unrestricted Upload of File with Dangerous Type