CVE-2023-6710
Executive Summary
CVE-2023-6710 exposes a stored XSS flaw in Apache’s mod_proxy_cluster. An attacker can inject a script via the ‘alias’ URL parameter, causing the server to create a new virtual host and embed the script into the cluster‑manager page. This allows arbitrary script execution in the context of the cluster manager, potentially leading to data theft or further compromise of the web application.
Authoritative CVE Metadata - CVSS Base Score: 5.4 (MEDIUM) - Published: 2023-12-12T22:15:22.950 - Last Modified: 2026-09-19T12:16:37.010
Original Description: A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.
"They must often change, who would be constant in happiness or wisdom."
— Confucius