CVE-2020-36891

Source
https://cve.org/CVERecord?id=CVE-2020-36891
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36891.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-36891
Published
2025-12-18T20:15:49.490Z
Modified
2026-03-10T23:20:59.776278Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.0.49"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36891.json"