CVE-2025-2878: Kentico CMS Additional Database Installation Wizard install.aspx cross site scripting
A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /CMSInstall/install.aspx of the component Additional Database Installation Wizard. The manipulation of the argument new database leads to cross site scripting. The attack can be launched remotely. Upgrading to version 13.0.179 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2878?
CVE-2025-2878 has been declared as problematic due to vulnerabilities in Kentico CMS versions up to 13.0.178.
How do I fix CVE-2025-2878?
To mitigate CVE-2025-2878, it is recommended to upgrade Kentico CMS to a version later than 13.0.178.
What components are affected by CVE-2025-2878?
CVE-2025-2878 affects the Additional Database Installation Wizard functionality in Kentico CMS.
What versions of Kentico CMS are impacted by CVE-2025-2878?
CVE-2025-2878 impacts Kentico CMS versions up to and including 13.0.178.
Is there a workaround for CVE-2025-2878 until a patch is applied?
Currently, there is no known workaround for CVE-2025-2878, so upgrading is the main recommended action.