CVE-2022-50686
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.04%
- CWE
- CWE-209
- Published
- 2025-12-18
- Last modified
- 2026-03-13
Affected products
- Kentico Xperience
Weakness type
Related vulnerabilities
- CVE-2025-68110 — ChurchCRM discloses database information on error message
- CVE-2025-62168 — Squid vulnerable to information disclosure via authentication credential leakage in error handling
- CVE-2025-47813 — loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
- CVE-2026-33192 — free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
- CVE-2025-71282 — XenForo Path Disclosure via open_basedir Exceptions
- CVE-2024-11625 — Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affec
- CVE-2025-36003 — IBM Security Verify Governance Identity Manager information disclosure
- CVE-2025-23320 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c