CVE-2021-47711: Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injection
A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47711?
CVE-2021-47711 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2021-47711?
To fix CVE-2021-47711, update Kentico Xperience to version 13.0.53 or later, which includes patches for this vulnerability.
Who is affected by CVE-2021-47711?
CVE-2021-47711 affects authenticated editors using Kentico Xperience version 13.0.52 and earlier.
What types of attacks can CVE-2021-47711 enable?
CVE-2021-47711 can enable attackers to perform unauthorized database access and potentially manipulate data.
Is CVE-2021-47711 an input validation issue?
Yes, CVE-2021-47711 arises from weak input validation in the online marketing macro method parameters.