Security Advisory

CVE-2019-25228

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-18 19:53:23
Last updated 2025-12-27 16:47:33
Assigner VulnCheck
CVSS score 5.1
State PUBLISHED

Description

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.