CVE-2024-58322

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-18 20:15

Updated : 2025-12-27 17:15


NVD link : CVE-2024-58322

Mitre link : CVE-2024-58322

CVE.ORG link : CVE-2024-58322


JSON object : View

Products Affected

kentico

  • xperience
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')