← Advisories

Kentico CMS <=5.5R2.23 Cross-Site Scripting POST Injection Vulnerability

Low
Advisory ID
ZSL-2011-5015
Release Date
31 May 2011
Vendor
Kentico Software - http://www.kentico.com
Affected Version
5.5R2.23 and bellow
CVE
N/A
Tested On
Microsoft Windows XP Pro SP3 (EN), Microsoft-IIS/7.5, ASP.NET 2.0.50727
Summary

.NET Web Content Management System for ASP.NET.

Description

Kentico CMS suffers from a XSS vulnerability when parsing user input to the 'userContextMenu_parameter' parameter via POST method in '/examples/webparts/membership/users-viewer.aspx'. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user's browser session.

Proof of Concept
Disclosure Timeline
12.03.2011Vulnerability discovered.
21.05.2011Vendor contacted with sent PoC files.
23.05.2011Vendor replies.
23.05.2011Asked vendor for confirmation.
24.05.2011Vendor confirms issue scheduling hotfix 5.5R2.24.
31.05.2011Coordinated public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
31.05.2011Initial release
01.06.2011Added reference [3] and [4]
02.06.2011Added reference [5]
03.06.2011Added reference [6]
13.06.2011Added reference [7]