CVE-2023-6013
CVE-2023-6013
5.4
MediumPublished:
Last updated:
Source:security@huntr.dev
Modified
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- Required
- Scope
- Changed
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None
Description
H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.
References
security@huntr.dev
https://huntr.com/bounties/9881569f-dc2a-437e-86b0-20d4b70ae7afaf854a3a-2127-422b-91ae-364da2661108
https://huntr.com/bounties/9881569f-dc2a-437e-86b0-20d4b70ae7af