CVE-2023-53934CWE-97

Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service

High · published December 18, 2025

CVSS v4.0
8.7
EPSS
0%
Percentile
34.9
In the wild
Unconfirmed
What it is

⚡ An attacker can easily send crafted requests to Kentico Xperience's GetResource handler, bringing your services to a grinding halt! Think of it like a delivery service where a malicious person sends an avalanche of fake orders, overwhelming the system and causing real customers to be left out in the cold. Just one poorly validated request can trigger chaos! If exploited, this vulnerability could mean your website becomes unreachable, leaving users frustrated and unable to access your services. In a digital world, that's like locking your doors during peak hours – absolutely devastating for your reputation and bottom line!

Put simply

Think of it like a delivery service where a malicious person sends an avalanche of fake orders, overwhelming the system and causing real customers to be left out in the cold. Just one poorly validated request can trigger chaos! This denial of service vulnerability arises from improper input validation within Kentico Xperience, allowing attackers to disrupt service availability by sending maliciously constructed requests to the GetResource handler.

What to do

If exploited, this vulnerability could mean your website becomes unreachable, leaving users frustrated and unable to access your services. In a digital world, that's like locking your doors during peak hours – absolutely devastating for your reputation and bottom line! To protect yourself, patch Kentico Xperience to the latest version as soon as possible and implement input validation checks to filter out harmful requests. Regularly monitor logs for unusual activity to stay ahead of potential attacks! You've got this! By taking these steps, you’ll reinforce your defenses and keep your services running smoothly! 🛡️

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00417 · 34.9th percentile
Weakness
CWE-97 · Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
Published
2025-12-18T19:53Z
EPSS history
Timeline
  • 18 DEC 19:53Z
    Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service
    cvelistv5