VYPR
Medium severityNVD Advisory· Published Jan 2, 2025· Updated Apr 15, 2026

CVE-2024-12907

CVE-2024-12907

Description

Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parameter sent to /CMSMessages/AccessDenied.aspx endpoint. Notably, support for this version of Kentico ended in 2016. Version 8 was tested as well and does not contain this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Kentico CMS version 7 has a reflected XSS via the GET request parameter sent to /CMSMessages/AccessDenied.aspx; version 7 is EOL since 2016.

Vulnerability

Overview

CVE-2024-12907 is a reflected cross-site scripting (XSS) vulnerability found in Kentico CMS version 7. The flaw resides in the improper neutralization of a specific GET request parameter sent to the /CMSMessages/AccessDenied.aspx endpoint, allowing an attacker to inject arbitrary JavaScript code into the response page [1].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious URL that includes the manipulated GET parameter and luring a victim to click it. No prior authentication is required, and the attack can be performed remotely as long as the victim can access the Kentico CMS instance. Version 8 of the product was tested and confirmed not to contain this vulnerability [1].

Impact

If successfully exploited, the attacker can execute arbitrary JavaScript in the context of the victim's session. This could lead to data theft (including session cookies), defacement, or redirection to malicious sites. The severity is considered Medium.

Mitigation

Kentico CMS version 7 reached end of life in 2016 and no longer receives security updates. The vendor recommends upgrading to a supported version. Currently, no patch is available for version 7; the only remediation is to migrate to a newer release, such as version 8 or later [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.