Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal network details. | |
| Title | Kentico Xperience <= 13.0.159 Authentication Information Disclosure | |
| First Time appeared |
Kentico
Kentico xperience |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kentico
Kentico xperience |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T21:18:59.622Z
Reserved: 2025-12-17T16:51:11.810Z
Link: CVE-2024-58320
Updated: 2025-12-18T21:17:43.928Z
Status : Analyzed
Published: 2025-12-18T20:15:53.933
Modified: 2025-12-24T16:39:35.703
Link: CVE-2024-58320
No data.
OpenCVE Enrichment
No data.