cve/2023/CVE-2023-52430.md
2024-06-18 02:51:15 +02:00

692 B

CVE-2023-52430

Description

The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.

POC

Reference

Github

No PoCs found on GitHub currently.