CVE-2025-2878 | Kentico CMS up to 13.0.178 Additional Database Installation Wizard /CMSInstall/install.aspx new database cross site scripting
A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /CMSInstall/install.aspx of the component Additional Database Installation Wizard. The manipulation of the argument new database leads to cross site scripting.
This vulnerability is known as CVE-2025-2878. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.