PT-2025-52300 · Kentico · Kentico Xperience

Published

2025-12-18

·

Updated

2025-12-19

·

CVE-2021-47711

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kentico Xperience (affected versions not specified)
Description A SQL injection issue exists in Kentico Xperience, potentially allowing authenticated editors to inject malicious SQL queries through online marketing macro method parameters. This is due to weaknesses in input validation for macro method inputs. Successful exploitation could lead to unauthorized database access and data manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-47711

Affected Products

Kentico Xperience