A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability through maliciously constructed requests.
References
| Link | Resource |
|---|---|
| https://devnet.kentico.com/download/hotfixes | Product |
| https://www.vulncheck.com/advisories/kentico-xperience-getresource-handler-denial-of-service | Third Party Advisory |
Configurations
History
24 Dec 2025, 17:01
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:* | |
| References | () https://devnet.kentico.com/download/hotfixes - Product | |
| References | () https://www.vulncheck.com/advisories/kentico-xperience-getresource-handler-denial-of-service - Third Party Advisory | |
| First Time |
Kentico
Kentico xperience |
18 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 20:15
Updated : 2025-12-24 17:01
NVD link : CVE-2023-53934
Mitre link : CVE-2023-53934
CVE.ORG link : CVE-2023-53934
JSON object : View
Products Affected
kentico
- xperience
CWE
CWE-97
Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
