An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls. | |
| Title | Kentico Xperience <= 12.0.0 User Widget Information Disclosure | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T21:48:29.671Z
Reserved: 2025-12-17T16:58:40.853Z
Link: CVE-2019-25230
Updated: 2025-12-18T21:09:39.984Z
Status : Received
Published: 2025-12-18T20:15:49.040
Modified: 2025-12-18T20:15:49.040
Link: CVE-2019-25230
No data.
OpenCVE Enrichment
No data.