Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8ch-p5g4-xj7g

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

** DISPUTED ** WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack.

** DISPUTED ** WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack.

EPSS

Процентиль: 93%
0.11226
Средний

7.5 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.5
nvd
около 8 лет назад

WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack

EPSS

Процентиль: 93%
0.11226
Средний

7.5 High

CVSS3

Дефекты

CWE-74