CVE-2022-50682: Kentico Xperience <= 13.0.79 Routing Engine CRLF Injection
A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50682?
CVE-2022-50682 is considered a critical vulnerability due to its potential for header injection and further exploitation.
How do I fix CVE-2022-50682?
To fix CVE-2022-50682, apply the latest hotfix provided by Kentico for Xperience version 13.0.79 or lower.
What can attackers do with CVE-2022-50682?
Attackers can exploit CVE-2022-50682 to manipulate URL query string redirects, potentially leading to further web application attacks.
Which versions of Kentico Xperience are affected by CVE-2022-50682?
CVE-2022-50682 affects Kentico Xperience versions up to and including 13.0.79.
How does CVE-2022-50682 exploit improper encoding?
CVE-2022-50682 exploits improper encoding in the routing engine, allowing for CRLF injection attacks that manipulate HTTP headers.