A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-12-12T22:01:34.359Z
Updated: 2024-11-24T12:38:26.983Z
Reserved: 2023-12-12T06:15:58.379Z
Link: CVE-2023-6710
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-12T22:15:22.950
Modified: 2024-11-21T08:44:24.533
Link: CVE-2023-6710
Redhat