CVE-2024-58320: Kentico Xperience
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal network details.
Affected products
- Kentico Xperience: up to and including 13.0.159
Published 2025-12-18. Last modified 2026-06-17.