CVE-2025-32369: XSS
Published Apr 6, 2025
·Updated
Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.
Affected Software
2 affected components
Kentico Xperience<13.0.181
Kentico Xperience<13.0.181
Event History
Apr 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32369?
CVE-2025-32369 is classified as a high severity vulnerability due to its potential for exploitation through stored XSS.
2
How do I fix CVE-2025-32369?
To fix CVE-2025-32369, update Kentico Xperience to version 13.0.181 or later.
3
Who is affected by CVE-2025-32369?
Authenticated users of Kentico Xperience versions prior to 13.0.181 are affected by CVE-2025-32369.
4
What type of vulnerability is CVE-2025-32369?
CVE-2025-32369 is a stored cross-site scripting (XSS) vulnerability.
5
What is the exploit vector for CVE-2025-32369?
The exploit vector for CVE-2025-32369 involves interactions with the media library file upload feature.