PT-2025-13408 · Kentico · Kentico Cms
C4Ng4C3Ir0
·
Published
2025-03-27
·
Updated
2025-03-29
·
CVE-2025-2878
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Kentico CMS versions up to 13.0.178
Description
A vulnerability was found in the Additional Database Installation Wizard component of Kentico CMS, specifically in the file /CMSInstall/install.aspx. The issue is related to the manipulation of the
new database argument, which leads to cross-site scripting. This can be exploited remotely.Recommendations
For versions up to 13.0.178, upgrade to version 13.0.179 to address this issue. It is recommended to upgrade the affected Additional Database Installation Wizard component.
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kentico Cms