AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-7205

MEDIUM · CVSS 4.8 EPSS 0.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-02-20 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.8. It affects Java. It may be remotely exploitable.

CVE
CVE-2018-7205
Severity
MEDIUM
CVSS
4.8
EPSS
0.83%
Java

Original NVD Description

Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design" screens. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout

Related CVEs

Other vulnerabilities affecting the same vendor(s)