S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Apr 2, 2025

CVE-2025-2748 Scanner

CVE-2025-2748 Scanner - Cross-Site Scripting (XSS) vulnerability in Kentico Xperience CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2748
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Xperienceby Kentico
0
Updated Aug 22, 2026View on NVD →
Detail

Kentico Xperience CMS is a popular web content management system used by organizations for building websites and online stores. It offers rich features for content management, e-commerce, and online marketing, making it a preferred choice for businesses looking to manage their digital channels. Configured to support enterprise needs, Kentico Xperience CMS is often found in medium to large-sized enterprises worldwide. Its integration capabilities with other software and user-friendly interface cater to a wide range of customers, from marketers to developers. The flexibility and scalability make it suitable for a variety of projects and industries. A robust ecosystem of extensions and integrations further enhances its functionality.

Cross-Site Scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web applications. This particular vulnerability in Kentico Xperience CMS arises due to insufficient validation and filtering of files uploaded via the multi-file upload feature. By exploiting this flaw, attackers can execute arbitrary scripts in the context of the user's session. Stored XSS can lead to session hijacking, phishing attacks, and other malicious activities. The injection points during file uploads are inadequately sanitized, leading to potential script execution when the file is accessed. Such vulnerabilities significantly impact user trust and the integrity of the affected application.

The vulnerability allows an attacker to upload malicious files via the MultiFileUploader.ashx endpoint, which lacks proper validation. The uploaded file is then used in conjunction with the GetResource.ashx endpoint where the injected script is executed, demonstrating the stored XSS. The files uploaded as .zip are accessed and rendered as SVG, where the payload is embedded. The vulnerability exploits the image parameter in the URL to render the malicious SVG file. The weak points are the lack of file type and content checks during the upload process. Technical execution involves crafting specially encoded payloads that trigger once the file is processed or accessed.

Exploiting this vulnerability can lead to numerous detrimental effects, such as unauthorized actions being triggered in the user's browser. Users' sessions could be hijacked, allowing attackers to impersonate users and access sensitive information. Phishing attacks could be facilitated by redirecting users to malicious sites controlled by the attacker. The brand reputation of the organization using Kentico Xperience CMS can be at risk if attackers are able to deliver harmful content via the compromised site. Malicious scripts could alter or destroy content, contributing to data integrity issues. Furthermore, the exploitation can be leveraged for broader attacks against the system or its users.

REFERENCES

Solution Advice
  • Apply the latest patches provided by Kentico to mitigate the XSS vulnerability.
  • Implement strict input validation and sanitize user inputs to remove possible script tags.
  • Restrict file types and content that can be uploaded through the multi-file upload feature.
  • Improve server-side checks to prevent the execution of unauthorized scripts.
  • Conduct regular security audits and assessments to identify and resolve vulnerabilities swiftly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.