CVE-2019-25228

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/ima...

medium 5.3 CVSS 3.1
Published: Dec 18, 2025
Modified: Dec 24, 2025
Vendor: Kentico
Product: Xperience

Description

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.

References

Related CVEs