Skip to content

Conversation

@jajik
Copy link
Member

@jajik jajik commented Feb 7, 2024

Backport from 2.0

Reporter: Mohamed Mounir Boudjema
Company: Intervalle-technologies

The issue lies in unencoded context and alias being embedded into the mod_manager webpage making it a vector for XSS attack. The impact is considered low as the webpage should not be accessible to the public.

@jajik jajik requested a review from jfclere February 7, 2024 14:20
@jajik
Copy link
Member Author

jajik commented Feb 7, 2024

@jfclere Thanks, merging.

@jajik jajik merged commit 1bca76b into modcluster:1.3.x Feb 7, 2024
@jajik jajik deleted the mod_manager branch February 8, 2024 07:33
@jajik jajik changed the title [1.3] Improve mod_manager's html output [1.3] Fix CVE-2023-6710 Apr 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants