PT-2025-12670 · Kentico · Kentico Xperience

Piotr Bazydlo

·

Published

2025-03-24

·

Updated

2025-12-27

·

CVE-2025-2748

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kentico Xperience versions prior to 13.0.178
Description The Kentico Xperience application does not fully validate or filter files uploaded through the multiple-file upload functionality. This insufficient validation allows for stored Cross-Site Scripting (XSS). Exploitation of this issue can potentially lead to Remote Code Execution (RCE) by abusing custom file handlers. The vulnerability is triggered by uploading specially crafted files, such as ZIP archives containing malicious SVG files, which can then be used to execute arbitrary JavaScript code.
Recommendations Versions prior to 13.0.178 should be updated to version 13.0.178 or later.

Fix

RCE

XSS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2748

Affected Products

Kentico Xperience