Kentico Xperience before 13.0.178 has a specific set of...
High severity
Unreviewed
Published
Apr 6, 2025
to the GitHub Advisory Database
•
Updated Apr 8, 2025
Description
Published by the National Vulnerability Database
Apr 6, 2025
Published to the GitHub Advisory Database
Apr 6, 2025
Last updated
Apr 8, 2025
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a separate issue not necessarily related to SVG or XSS.
References