An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
panel/login in Kirby v2.5.12 allows XSS via a blog name.
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.