CVE-2025-32370

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 6, 2025
Updated: Apr 8, 2025
CWE ID 434
CWE ID 912

Summary

CVE-2025-32370 is a vulnerability affecting Kentico Xperience versions prior to 13.0.178. Despite limiting unauthenticated file uploads to a specific set of extensions, the platform's TryZipProviderSafe function expands this capability to process .zip files, allowing for the creation of files with other extensions. This issue is distinct from known vulnerabilities concerning SVG or XSS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share