CVE-2023-6199

Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
References
Link Resource
https://fluidattacks.com/advisories/imagination/ Exploit Third Party Advisory
https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ Product Release Notes Vendor Advisory
https://fluidattacks.com/advisories/imagination/ Exploit Third Party Advisory
https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ Product Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:bookstackapp:bookstack:23.10.2:*:*:*:*:*:*:*

History

19 May 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 6.5
Summary (en) Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF. (en) Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.

Information

Published : 2023-11-20 23:15

Updated : 2025-05-19 14:15


NVD link : CVE-2023-6199

Mitre link : CVE-2023-6199

CVE.ORG link : CVE-2023-6199


JSON object : View

Products Affected

bookstackapp

  • bookstack
CWE
CWE-918

Server-Side Request Forgery (SSRF)