CVE-2022-50685

Source
https://cve.org/CVERecord?id=CVE-2022-50685
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50685.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-50685
Published
2025-12-18T20:15:50.753Z
Modified
2026-03-11T12:36:44.519737Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "13.0.56"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50685.json"