PT-2025-52294 · Kentico · Xperience

Published

2025-12-18

·

Updated

2025-12-18

·

CVE-2019-25228

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kentico Xperience (affected versions not specified)
Description An information disclosure issue allows the leakage of virtual context URLs through the HTTP Referer header. This occurs when users interact with third-party domains, potentially exposing sensitive virtual context information to external domains during link and image loading or through page builder interactions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2019-25228

Affected Products

Xperience