CVE-2022-50684: Kentico Xperience <= 13.0.71 Form Emails HTML Injection
An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50684?
CVE-2022-50684 is considered a medium severity vulnerability due to its potential for HTML content execution in email clients.
How do I fix CVE-2022-50684?
To fix CVE-2022-50684, ensure that form submission values are properly encoded before inclusion in emails.
Who is affected by CVE-2022-50684?
CVE-2022-50684 affects users of Kentico Xperience versions up to and including 13.0.71.
What type of vulnerability is CVE-2022-50684?
CVE-2022-50684 is an HTML injection vulnerability that allows attackers to inject malicious HTML into form submission emails.
What can be the consequences of CVE-2022-50684?
The consequences of CVE-2022-50684 may include email security compromise and the execution of malicious HTML in recipient email clients.