CVE-2020-36891
18.12.2025, 20:15
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.
| Vendor | Product | Version |
|---|---|---|
| kentico | xperience | 𝑥 ≤ 12.0.49 |
𝑥
= Vulnerable software versions