Description
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.
Problem types
Generation of Error Message Containing Sensitive Information
Product status
Credits
Kentico Security Team
References
devnet.kentico.com/download/hotfixes (Kentico DevNet Hotfixes)
www.vulncheck.com/...ine-form-control-information-disclosure (VulnCheck Advisory: Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.