CVE-2021-46163: XSS
Published Jan 9, 2022
·Updated
Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem.
Affected Software
2 affected components
Kentico Kentico CMS=13.0.44
Kentico Xperience=13.0.44
Event History
Jan 9, 2022
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
Description
Jan 10, 2022
Data Sourced
via NVD·02:11 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-46163?
CVE-2021-46163 has a moderate severity level due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2021-46163?
To fix CVE-2021-46163, you should update Kentico Xperience to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2021-46163?
CVE-2021-46163 specifically affects Kentico Xperience version 13.0.44.
4
What type of attack does CVE-2021-46163 facilitate?
CVE-2021-46163 facilitates cross-site scripting (XSS) attacks through the Media Libraries subsystem.
5
Can CVE-2021-46163 be exploited without authentication?
Yes, CVE-2021-46163 can potentially be exploited by an unauthenticated user if they can upload an XML document.