CVE-2020-36891: Kentico Xperience <= 12.0.49 File Upload Stored XSS
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36891?
CVE-2020-36891 is considered a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2020-36891?
To fix CVE-2020-36891, update Kentico Xperience to version 12.0.50 or later.
What type of vulnerability is CVE-2020-36891?
CVE-2020-36891 is a stored cross-site scripting (XSS) vulnerability.
Which versions of Kentico Xperience are affected by CVE-2020-36891?
CVE-2020-36891 affects Kentico Xperience versions up to and including 12.0.49.
What can attackers do with CVE-2020-36891?
Attackers can exploit CVE-2020-36891 by uploading files with manipulated MIME types to execute malicious scripts.