CVE-2022-50681: Kentico Xperience <= 13.0.88 Rich Text Editor Reflected XSS
A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via administration input fields in the Rich text editor component. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50681?
CVE-2022-50681 is classified as a reflected cross-site scripting (XSS) vulnerability, which can severely impact user security.
How do I fix CVE-2022-50681?
To fix CVE-2022-50681, you should apply the security updates provided by Kentico for Xperience versions up to 13.0.88.
Who is affected by CVE-2022-50681?
CVE-2022-50681 affects users of Kentico Xperience versions up to and including 13.0.88.
What can attackers do with CVE-2022-50681?
Attackers can exploit CVE-2022-50681 to inject and execute arbitrary scripts in the browsers of users interacting with vulnerable admin input fields.
Is CVE-2022-50681 a serious threat to Kentico Xperience users?
Yes, CVE-2022-50681 poses a serious threat as it allows for script execution in user sessions, which can lead to data theft and other malicious activities.