CVE-2018-7205

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/02/2018
Last modified:
05/08/2024

Description

Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design" screens. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kentico:kentico_cms:*:*:*:*:*:*:*:* 9.0 (including) 11.0 (including)


References to Advisories, Solutions, and Tools