CVE-2022-50685: Kentico Xperience <= 13.0.56 File Upload Stored XSS
A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50685?
CVE-2022-50685 has been classified as a high severity vulnerability due to its potential for allowing stored cross-site scripting attacks.
How do I fix CVE-2022-50685?
To fix CVE-2022-50685, ensure that you update Kentico Xperience to version 13.0.57 or later, which addresses this vulnerability.
What types of files are affected by CVE-2022-50685?
CVE-2022-50685 affects XML file uploads that are used as page attachments or metafiles within Kentico Xperience.
Who is affected by CVE-2022-50685?
Authenticated users of Kentico Xperience versions up to 13.0.56 are affected by CVE-2022-50685.
How can attackers exploit CVE-2022-50685?
Attackers can exploit CVE-2022-50685 by uploading malicious XML files that execute scripts upon being accessed by users.