PT-2025-52308 · Kentico · Kentico Xperience

Published

2025-12-18

·

Updated

2025-12-19

·

CVE-2022-50686

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kentico Xperience (affected versions not specified)
Description An information disclosure issue exists in Kentico Xperience. Attackers can view sensitive stack trace details through Portal Engine form control error messages. This disclosure of internal system information and implementation details could potentially be exploited by unauthorized users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-50686

Affected Products

Kentico Xperience