AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-12907

UNKNOWN · CVSS N/A EPSS 0.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-01-02 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.

CVE
CVE-2024-12907
Severity
UNKNOWN
CVSS
N/A
EPSS
0.39%

Original NVD Description

Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parameter sent to /CMSMessages/AccessDenied.aspx endpoint. Notably, support for this version of Kentico ended in 2016. Version 8 was tested as well and does not contain this vulnerability.