CVE-2020-36889

Source
https://cve.org/CVERecord?id=CVE-2020-36889
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36889.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-36889
Published
2025-12-18T20:15:49.200Z
Modified
2026-03-10T23:19:47.427834Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.0.90"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36889.json"