CVE-2023-53738: Kentico Xperience <= 13.0.109 Page Preview Reflected XSS
A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53738?
CVE-2023-53738 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2023-53738?
To fix CVE-2023-53738, update Kentico Xperience to the latest version beyond 13.0.109 where the vulnerability has been addressed.
Who is affected by CVE-2023-53738?
Authenticated users of Kentico Xperience versions up to 13.0.109 are at risk of CVE-2023-53738.
What types of attacks can exploit CVE-2023-53738?
CVE-2023-53738 can be exploited to conduct reflected cross-site scripting attacks, allowing attackers to execute arbitrary scripts in users' browsers.
Is there a mitigation for CVE-2023-53738?
As an immediate mitigation for CVE-2023-53738, restrict access to page preview URLs for untrusted users until the software is updated.