CVE-2023-53934
A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability through maliciously constructed requests.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-97
- Published
- 2025-12-18
- Last modified
- 2026-03-13
Affected products
- Kentico Xperience
Weakness type
Related vulnerabilities
- CVE-2025-36558 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CVE-2025-35996 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CVE-2025-21103 — Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7...
- CVE-2024-56363 — APTRS has SSTI vulnerability