CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. See the original NVD description below for full technical details.
CVE
CVE-2019-25228
Severity
MEDIUM
CVSS
5.3
EPSS
0.26%
Original NVD Description
An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.
Related CVEs
Other vulnerabilities affecting the same vendor(s)