A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through existing hashing mechanisms. The hotfix introduces an additional security layer to prevent hash value reuse and potential exploitation.
References
| Link | Resource |
|---|---|
| https://devnet.kentico.com/download/hotfixes | Product |
| https://www.vulncheck.com/advisories/kentico-xperience-url-hashing-cryptography-vulnerability | Third Party Advisory |
Configurations
History
24 Dec 2025, 18:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Kentico
Kentico xperience |
|
| CPE | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| References | () https://devnet.kentico.com/download/hotfixes - Product | |
| References | () https://www.vulncheck.com/advisories/kentico-xperience-url-hashing-cryptography-vulnerability - Third Party Advisory |
18 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 20:15
Updated : 2025-12-24 18:14
NVD link : CVE-2021-47712
Mitre link : CVE-2021-47712
CVE.ORG link : CVE-2021-47712
JSON object : View
Products Affected
kentico
- xperience
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
