An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users. | |
| Title | Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-209 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T21:19:43.244Z
Reserved: 2025-12-17T16:56:31.872Z
Link: CVE-2022-50686
Updated: 2025-12-18T21:17:48.842Z
Status : Received
Published: 2025-12-18T20:15:50.897
Modified: 2025-12-18T20:15:50.897
Link: CVE-2022-50686
No data.
OpenCVE Enrichment
No data.