CVE-2022-50682

MEDIUM

Kentico Xperience - CRLF Injection

Title source: llm

Description

A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-93
Status published

Affected Products (1)

kentico/xperience < 13.0.79

Timeline

Published Dec 18, 2025
Tracked Since Feb 18, 2026