Description
An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal network details.
Problem types
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
Credits
Bank of Ayudhya
References
devnet.kentico.com/download/hotfixes (Kentico DevNet Hotfixes)
www.vulncheck.com/...e-authentication-information-disclosure (VulnCheck Advisory: Kentico Xperience <= 13.0.159 Authentication Information Disclosure)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.