A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through existing hashing mechanisms. The hotfix introduces an additional security layer to prevent hash value reuse and potential exploitation.
History

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through existing hashing mechanisms. The hotfix introduces an additional security layer to prevent hash value reuse and potential exploitation.
Title Kentico Xperience <= 12.0.102 URL Hashing Cryptography Vulnerability
First Time appeared Kentico
Kentico xperience
Weaknesses CWE-327
CPEs cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
Vendors & Products Kentico
Kentico xperience
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-18T19:53:26.971Z

Updated: 2025-12-18T21:48:02.746Z

Reserved: 2025-12-05T19:10:29.046Z

Link: CVE-2021-47712

cve-icon Vulnrichment

Updated: 2025-12-18T21:08:30.377Z

cve-icon NVD

Status : Received

Published: 2025-12-18T20:15:49.810

Modified: 2025-12-18T20:15:49.810

Link: CVE-2021-47712

cve-icon Redhat

No data.