CVE-2022-50683: Kentico Xperience <= 13.0.74 Form Configuration Stored XSS
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration. This allows malicious scripts to execute in users' browsers through unvalidated form configuration settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50683?
CVE-2022-50683 is classified as a medium severity vulnerability due to its potential impact on user security.
How do I fix CVE-2022-50683?
To fix CVE-2022-50683, update Kentico Xperience to a patched version beyond 13.0.74.
What types of attacks can be executed through CVE-2022-50683?
CVE-2022-50683 allows for stored cross-site scripting attacks, enabling the injection of malicious scripts into users' browsers.
Which versions of Kentico Xperience are affected by CVE-2022-50683?
CVE-2022-50683 affects Kentico Xperience versions up to and including 13.0.74.
What are the potential consequences of exploiting CVE-2022-50683?
Exploiting CVE-2022-50683 can lead to unauthorized actions being performed in the context of the affected user's session.