Beveiligingsadvies

CVE-2019-25228

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-18 19:53:23
Laatst bijgewerkt 2025-12-27 16:47:33
Toegewezen door VulnCheck
CVSS-score 5.3
Status PUBLISHED

Beschrijving

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.