CVE-2023-6710

All FrameworksJBoss/WildFlyCWE-79CVE-2023-6710

CVE-2023-6710

State: PUBLISHED · Published: 2023-12-12 · Updated: 2025-11-20 · Assigner: redhat
Description
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/6xxx/CVE-2023-6710.json