CVE-2024-58318

Source
https://cve.org/CVERecord?id=CVE-2024-58318
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58318.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58318
Published
2025-12-18T20:15:53.637Z
Modified
2026-03-12T17:13:33.238669Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in users' browsers.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58318.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "13.0.162"
            }
        ]
    }
]