← back
CVE-2021-47711

Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injection

CVSS 8.7 HIGHEPSS 0.3%CWE-89
A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Affected products
Kentico · Xperience

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →