← back
CVE-2019-25230

Kentico Xperience <= 12.0.0 User Widget Information Disclosure

CVSS 5.3 MEDIUMEPSS 0.2%CWE-497
An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Kentico · Xperience

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →