2023-12-26 23:00:28 +00:00

24 lines
878 B
JSON

{
"id": "CVE-2023-48003",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-12-26T22:15:13.907",
"lastModified": "2023-12-26T22:15:13.907",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv=\"refresh\"' in the WebSocket messages."
}
],
"metrics": {},
"references": [
{
"url": "https://docs.unsafe-inline.com/0day/asp.net-zero-v12.3.0-html-injection-leads-to-open-redirect-via-websockets-cve-2023-48003",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/passtheticket/vulnerability-research/blob/main/aspnetzero_html_injection_via_websockets_messages.md",
"source": "cve@mitre.org"
}
]
}