CVE-2023-52430
Description
The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in caddy-security plugin 1.1.20 allows arbitrary JavaScript execution via crafted URLs starting with /admin or /settings/mfa/delete/.
The caddy-security plugin version 1.1.20 for the Caddy web server contains a reflected cross-site scripting (XSS) vulnerability [1][3]. An attacker can inject arbitrary JavaScript by submitting a GET request to a URL that includes an XSS payload and begins with either /admin or /settings/mfa/delete/. The vulnerability stems from insufficient sanitization of user input reflected in the response [2].
Exploitation
Attackers can exploit this by tricking a victim into clicking a crafted link or by embedding the malicious URL in an iframe. No authentication is required to trigger the reflection, as the vulnerability exists in the URL handling logic. The attack surface includes any application using the vulnerable plugin version where users can be directed to such URLs [1].
Impact
Successful exploitation leads to full XSS, allowing the attacker to execute arbitrary JavaScript in the victim's browser context. This can result in session hijacking, credential theft, defacement, or other client-side attacks that compromise user data and integrity of the application [1][3].
Mitigation
The vulnerability is fixed in a later version of the plugin. Users should upgrade to the latest release immediately. No workaround is available. The issue was reported by Trail of Bits and documented in the project's issue tracker [1][2].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/greenpau/caddy-securityGo | <= 1.1.20 | — |
Affected products
2- Caddy/caddy-security plugindescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-xwmv-cx7p-fqfcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-52430ghsaADVISORY
- blog.trailofbits.com/2023/09/18/security-flaws-in-an-sso-plugin-for-caddyghsaWEB
- github.com/greenpau/caddy-security/issues/264ghsaWEB
- blog.trailofbits.com/2023/09/18/security-flaws-in-an-sso-plugin-for-caddy/mitre
News mentions
0No linked articles in our index yet.