CVE-2019-19493

MEDIUM

Kentico Xperience 9.0-12.0.49 - Cross-Site Scripting via Inconsistent Content-Type Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-19493. PoCs published by Ataberk YAVUZER.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Kentico CMS versions 9.0 to 12.0.49 by uploading a malicious SVG file with an inconsistent Content-Type header, leading to arbitrary JavaScript execution when the avatar is viewed.

Description

Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.

Exploits (1)

exploitdb WORKING POC
by Ataberk YAVUZER · textwebappsphp
https://www.exploit-db.com/exploits/48864

This exploit demonstrates a persistent XSS vulnerability in Kentico CMS versions 9.0 to 12.0.49 by uploading a malicious SVG file with an inconsistent Content-Type header, leading to arbitrary JavaScript execution when the avatar is viewed.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Kentico CMS 9.0-12.0.49
Auth required
Prerequisites: Valid credentials for Kentico Admin Panel · Ability to intercept and modify HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_misc
https://devnet.kentico.com/download/hotfixes

Scores

CVSS v3 5.4
EPSS 0.0202
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-434 CWE-706
Status published
Products (1)
kentico/xperience 9.0 - 12.0.50
Published Dec 02, 2019
Tracked Since Feb 18, 2026