cve/2023/CVE-2023-52430.md
2024-08-05 18:41:32 +00:00

703 B

CVE-2023-52430

Description

The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.

POC

Reference

Github