Skip to content

Conversation

@jajik
Copy link
Member

@jajik jajik commented Feb 7, 2024

Reporter: Mohamed Mounir Boudjema
Company: Intervalle-technologies

The issue lies in unencoded context and alias being embedded into the mod_manager webpage making it a vector for XSS attack. The impact is considered low as the webpage should not be accessible to the public.

@jajik
Copy link
Member Author

jajik commented Feb 7, 2024

Merging, thank you for the review!

@jajik jajik merged commit bc2c3cf into modcluster:main Feb 7, 2024
@rhusar
Copy link
Member

rhusar commented Feb 7, 2024

LGTM, thanks.

@jajik jajik deleted the mod_manager branch February 8, 2024 07:35
@jajik jajik changed the title Improve mod_manager's output Fix CVE-2023-6710 Apr 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants