CVE-2019-25228 Details
Description
An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.
A vulnerability allowing information disclosure has been identified in Kentico Xperience versions through 12.0.47. This vulnerability allows attackers to leak sensitive virtual context URLs via the HTTP Referer header when users interact with third-party domains. The exposed information can be accessed by external domains through page builder interactions and the loading of links or images.
Users can upgrade to Kentico Xperience version 13.0.198 or later, where this vulnerability has been addressed. Instructions for applying the hotfix are available on the Kentico Xperience DevNet.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://devnet.kentico.com/download/hotfixes | [email protected] | Product |
| https://www.vulncheck.com/advisories/kentico-xperience-virtual-context-information-disclosure | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kentico xperience | <= 12.0.47 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 24, 2025 | Initial Analysis | [email protected] |
| Dec 18, 2025 | New CVE Received | [email protected] |