PT-2025-13408 · Kentico · Kentico Cms

C4Ng4C3Ir0

·

Published

2025-03-27

·

Updated

2025-03-29

·

CVE-2025-2878

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Kentico CMS versions up to 13.0.178
Description A vulnerability was found in the Additional Database Installation Wizard component of Kentico CMS, specifically in the file /CMSInstall/install.aspx. The issue is related to the manipulation of the new database argument, which leads to cross-site scripting. This can be exploited remotely.
Recommendations For versions up to 13.0.178, upgrade to version 13.0.179 to address this issue. It is recommended to upgrade the affected Additional Database Installation Wizard component.

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2878

Affected Products

Kentico Cms