CVE-2019-25230: Kentico Xperience <= 12.0.0 User Widget Information Disclosure
Published Dec 18, 2025
·Updated
An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.
Affected Software
2 affected components
Kentico Xperience<=12.0.0
Kentico Xperience<=12.0
Event History
Dec 18, 2025
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-25230?
CVE-2019-25230 is classified as an information disclosure vulnerability.
2
How do I fix CVE-2019-25230?
To fix CVE-2019-25230, update Kentico Xperience to a version later than 12.0.0.
3
Who is affected by CVE-2019-25230?
CVE-2019-25230 affects authenticated users of Kentico Xperience up to version 12.0.0.
4
What can attackers do with CVE-2019-25230?
Attackers can exploit CVE-2019-25230 to access unauthorized system information via the live site widget properties dialog.
5
Is there a workaround for CVE-2019-25230?
There is no official workaround for CVE-2019-25230; upgrading to a secure version is recommended.