Описание
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.
Уязвимые конфигурации
Конфигурация 1Версия до 12.0 (включая)
cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00044
Низкий
7.5 High
CVSS3
Дефекты
CWE-209
Связанные уязвимости
CVSS3: 5.3
github
около 2 месяцев назад
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.
EPSS
Процентиль: 13%
0.00044
Низкий
7.5 High
CVSS3
Дефекты
CWE-209