Kentico Xperience
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*
- <= 12.0
A vulnerability allowing information disclosure has been identified in Kentico Xperience versions through 12.0. This issue arises within the Portal Engine form control, where error messages can inadvertently reveal sensitive stack trace details. Such detailed error messages may expose internal system information and implementation specifics to unauthorized users.
Exploitation of this vulnerability could lead to unauthorized access to sensitive internal information and implementation details, potentially aiding in further attacks.
Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found in the Kentico Xperience Documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.