CVE Published: 12/12/2023 |
CVE Updated: 24/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: JBoss Core Services for RHEL 8 Status : PUBLISHED
CVE-2023-6710 Description
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the \'alias\' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.