Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 12.0.0
A vulnerability allowing information disclosure exists in Kentico Xperience versions through 12.0.0. This issue allows authenticated users to access sensitive system objects via the live site widget properties dialog. The vulnerability arises from inadequate access controls, enabling unauthorized access to system information.
Exploitation of this vulnerability could lead to unauthorized access to sensitive system information.
Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.