CVE-2025-2878

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Mar 27, 2025
Updated: Mar 28, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-2878 is a newly disclosed vulnerability affecting Kentico CMS versions up to 13.0.178. The issue lies in an unknown functionality of the /CMSInstall/install.aspx file in the Additional Database Installation Wizard component. Manipulation of the 'new database' argument triggers cross-site scripting (XSS), posing a remote attack risk. To mitigate this vulnerability, it is suggested to upgrade to the latest version, 13.0.179.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share