Kentico Xperience <= 13.0.71 Form Emails HTML Injection
Vulnerability Description
An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50684
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Liam Goldfinch (NetConstruct)
References
More from Kentico
View All →Affected Vendor
Kentico
View all reports →