SQL Injection Affecting kentico.xperience.libraries package, versions [,13.0.53)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DOTNET-KENTICOXPERIENCELIBRARIES-14545482
  • published21 Dec 2025
  • disclosed18 Dec 2025
  • creditUnknown

Introduced: 18 Dec 2025

CVE-2021-47711  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade Kentico.Xperience.Libraries to version 13.0.53 or higher.

Overview

Kentico.Xperience.Libraries is a package for libraries and applications that use Kentico Xperience API.

Affected versions of this package are vulnerable to SQL Injection via the whereCondition parameter of the DidActivity macro method in the ContactInfoMethods class. An authenticated editor can gain unauthorized access to data or make unauthorized modifications in the database by adding a malicious SQL query as the macro method parameter.

CVSS Base Scores

version 4.0
version 3.1