Kentico Xperience是Kentico公司的一个数字体验平台。 Kentico Xperience 13.0.178及之前版本存在安全漏洞,该漏洞源于容易受到存储型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2748.yaml | POC Details |
| 2 | PoC for CVE-2025-2748 - Unauthenticated ZIP file upload with embedded SVG for XSS | https://github.com/xirtam2669/Kentico-Xperience-before-13.0.178---XSS-POC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-2747 | 9.8 CRITICAL | Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass |
| CVE-2025-2746 | 9.8 CRITICAL | Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass |
| CVE-2025-2749 | 7.2 HIGH | Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE |
No comments yet