---
title: Security advisory 2024-11-14
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

## Self-cross-site scripting (XSS) attack via Rich text editor

**CVSS**: 4.8\
**Affected versions**: 22.0.0 - 29.6.3\
**Category**: XSS

### Summary

The [rich text editor](https://docs.kentico.com/documentation/business-users/rich-text-editor.md) in the administration was vulnerable to self-cross-site scripting attacks (XSS) due to improper input validation when switching between _Text_ and _Code View_ mode. To eliminate this vulnerability, additional sanitization was added to the switch of the view mode action.

### How to fix

Update to the latest version. See [Update Xperience by Kentico projects](https://docs.kentico.com/documentation/developers-and-admins/installation/update-xperience-by-kentico-projects.md) for detailed instructions.
