Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kentico Xperience <= 13.0.71 Form Emails HTML Injection
Vulnerability Description
An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Kentico Xperience 跨站脚本漏洞
Vulnerability Description
Kentico Xperience是Kentico公司的一个数字体验平台。 Kentico Xperience存在跨站脚本漏洞,该漏洞源于未编码的表单字段可能被注入恶意HTML值,导致HTML注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A