Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13803

Опубликовано: 01 дек. 2025
Источник: nvd
CVSS3: 7.3
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.

EPSS

Процентиль: 18%
0.00056
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-644

Связанные уязвимости

CVSS3: 7.3
github
2 месяца назад

A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.

EPSS

Процентиль: 18%
0.00056
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-644