CVE-2023-6199

Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
References
Link Resource
https://fluidattacks.com/advisories/imagination/ Exploit Third Party Advisory
https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ Product Release Notes Vendor Advisory
https://fluidattacks.com/advisories/imagination/ Exploit Third Party Advisory
https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ Product Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:bookstackapp:bookstack:23.10.2:*:*:*:*:*:*:*

History

19 May 2025, 14:15

Type Values Removed Values Added
Summary (en) Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF. (en) Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 6.5

21 Nov 2024, 08:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.1
References () https://fluidattacks.com/advisories/imagination/ - Exploit, Third Party Advisory () https://fluidattacks.com/advisories/imagination/ - Exploit, Third Party Advisory
References () https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ - Product, Release Notes, Vendor Advisory () https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ - Product, Release Notes, Vendor Advisory

07 Jun 2024, 14:12

Type Values Removed Values Added
CPE cpe:2.3:a:bookstackapp:book_stack:23.10.2:*:*:*:*:*:*:* cpe:2.3:a:bookstackapp:bookstack:23.10.2:*:*:*:*:*:*:*
First Time Bookstackapp bookstack

29 Nov 2023, 17:28

Type Values Removed Values Added
CWE CWE-918
CPE cpe:2.3:a:bookstackapp:book_stack:23.10.2:*:*:*:*:*:*:*
References () https://fluidattacks.com/advisories/imagination/ - () https://fluidattacks.com/advisories/imagination/ - Exploit, Third Party Advisory
References () https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ - () https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/ - Product, Release Notes, Vendor Advisory
First Time Bookstackapp book Stack
Bookstackapp
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

20 Nov 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-20 23:15

Updated : 2025-05-19 14:15


NVD link : CVE-2023-6199

Mitre link : CVE-2023-6199

CVE.ORG link : CVE-2023-6199


JSON object : View

Products Affected

bookstackapp

  • bookstack
CWE
CWE-918

Server-Side Request Forgery (SSRF)