"value":"Reflected Cross-Site Scripting vulnerability in \"Design\" on \"Edit device layout\" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the \"Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design\" screens. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout"
"value":"** EN DISPUTA ** Vulnerabilidad de Cross-Site Scripting (XSS) reflejado en \"Design\" en \"Edit device layout\" en Kentico, de la versi\u00f3n 9 a la 11, permite que atacantes remotos ejecuten JavaScrpit malicioso mediante un par\u00e1metro devicename malicioso en un enlace al que se accede mediante las pantallas \"Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design\". NOTA: el fabricante ha respondido que existe una funcionalidad planeada para que usuarios autorizados editen y actualicen el dise\u00f1o de c\u00f3digo ascx."