Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design" screens. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://www.securityfocus.com/archive/1/541792/100/0/threaded |
|
History
Fri, 19 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kentico xperience
|
|
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico kentico Cms
|
Kentico xperience
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:24:11.480Z
Reserved: 2018-02-17T00:00:00.000Z
Link: CVE-2018-7205
No data.
Status : Modified
Published: 2018-02-20T15:29:00.663
Modified: 2025-12-19T20:56:46.070
Link: CVE-2018-7205
No data.
OpenCVE Enrichment
No data.
Weaknesses