PT-2025-52304 · Kentico · Kentico Xperience

Tom Waldman

·

Published

2025-12-18

·

Updated

2025-12-24

·

CVE-2022-50682

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Kentico Xperience (affected versions not specified)
Description A CRLF injection flaw exists in Kentico Xperience due to improper encoding within the routing engine. This allows attackers to manipulate URL query string redirects. Successful exploitation could lead to header injection and potentially enable further web application attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2022-50682

Affected Products

Kentico Xperience