Medium severity6.5NVD Advisory· Published Nov 20, 2023· Updated Jun 17, 2026
CVE-2023-6199
CVE-2023-6199
Description
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=23.10.2
- BookStack/BookStackv5Range: 23.10.2
- cpe:2.3:a:bookstackapp:bookstack:23.10.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- fluidattacks.com/advisories/imagination/nvdExploitThird Party Advisory
- www.bookstackapp.com/blog/bookstack-release-v23-10-3/nvdProductRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.