ZeroHour

CVE-2023-48003

PoC ×2
CVSS 3.1
6.1 medium
EPSS
<1%p39
Published
()
Modified
Description

An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

Vendors
aspnetzero
Products
asp.net zero
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.