CVE-2020-24794: XSS
Published Sep 9, 2020
·Updated
Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
Affected Software
2 affected components
Kentico Kentico<12.0.75
Kentico Xperience<12.0.75
Event History
Sep 9, 2020
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-24794?
CVE-2020-24794 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2020-24794?
To fix CVE-2020-24794, you should upgrade Kentico to version 12.0.75 or later.
3
What types of attacks can exploit CVE-2020-24794?
CVE-2020-24794 can be exploited to execute arbitrary JavaScript in the user's browser.
4
Which versions of Kentico are affected by CVE-2020-24794?
CVE-2020-24794 affects all versions of Kentico prior to 12.0.75.
5
Is there a way to mitigate the risk of CVE-2020-24794 without an upgrade?
Without upgrading, you can sanitize user inputs to reduce the risk of XSS attacks related to CVE-2020-24794.