Description
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9113 | Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS. |
References
History
Fri, 19 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kentico xperience
|
|
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico kentico
|
Kentico xperience
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:16:47.416Z
Reserved: 2019-12-02T00:00:00.000Z
Link: CVE-2019-19493
No data.
Status : Modified
Published: 2019-12-02T03:15:11.723
Modified: 2025-12-19T20:48:04.273
Link: CVE-2019-19493
No data.
OpenCVE Enrichment
No data.
EUVD