CVE ID | CVE-2024-12907 |
Publication date | 02 January 2025 |
Vendor | Kentico |
Product | Kentico CMS |
Vulnerable versions | 7 |
Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Kentico CMS (Cross-site Scripting) software and participated in coordination of its disclosure.
Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parameter sent to /CMSMessages/AccessDenied.aspx
endpoint.
Notably, support for this version of Kentico ended in 2016 and the vendor recommends upgrading to a newer version.
This vulnerability has been assigned CVE-2024-12907 and was not found while testing Kentico 8.
Credits
We thank Michał Majchrowicz and Marcin Wyczechowski (Afine Team) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.