A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability through maliciously constructed requests.
History

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability through maliciously constructed requests.
Title Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service
First Time appeared Kentico
Kentico xperience
Weaknesses CWE-97
CPEs cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
Vendors & Products Kentico
Kentico xperience
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-18T19:53:32.524Z

Updated: 2025-12-18T21:47:23.467Z

Reserved: 2025-12-16T19:22:09.997Z

Link: CVE-2023-53934

cve-icon Vulnrichment

Updated: 2025-12-18T21:04:39.075Z

cve-icon NVD

Status : Received

Published: 2025-12-18T20:15:51.530

Modified: 2025-12-18T20:15:51.530

Link: CVE-2023-53934

cve-icon Redhat

No data.