CVE-2023-53736: Kentico Xperience <= 13.0.120 Administration Interface Reflected XSS
A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53736?
CVE-2023-53736 is rated as a high severity reflected cross-site scripting vulnerability affecting Kentico Xperience.
How do I fix CVE-2023-53736?
To fix CVE-2023-53736, update Kentico Xperience to version 13.0.120 or later.
Who is affected by CVE-2023-53736?
Authenticated users of Kentico Xperience version 13.0.120 or earlier are affected by CVE-2023-53736.
What types of attacks can be executed using CVE-2023-53736?
Attackers can exploit CVE-2023-53736 to inject and execute arbitrary scripts in the administration interface.
Is my version of Kentico Xperience vulnerable to CVE-2023-53736?
If you are using Kentico Xperience version 13.0.120 or earlier, your system is vulnerable to CVE-2023-53736.