Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwcq-vxfg-777g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

EPSS

Процентиль: 95%
0.16676
Средний

8.6 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.6
nvd
больше 6 лет назад

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

EPSS

Процентиль: 95%
0.16676
Средний

8.6 High

CVSS3

Дефекты

CWE-94