CVE-2020-36889: Kentico Xperience <= 12.0.90 Administration Interface Stored XSS
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36889?
CVE-2020-36889 is rated as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2020-36889?
To fix CVE-2020-36889, apply the latest security updates provided by Kentico for Xperience version 12.0.90 and above.
Who is affected by CVE-2020-36889?
CVE-2020-36889 affects administrators using Kentico Xperience up to and including version 12.0.90.
What kind of attack is CVE-2020-36889?
CVE-2020-36889 is a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into error messages.
What are the consequences of CVE-2020-36889?
If exploited, CVE-2020-36889 can lead to the execution of malicious scripts in users' browsers when viewing error messages in the administration interface.