CVE-2023-48003: Aspnetzero ASP.NET Zero

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

Affected products

  • Aspnetzero ASP.NET Zero: before 12.3.0 (fixed in 12.3.0)

Published 2023-12-26. Last modified 2026-06-17.