Логотип exploitDog
bind:CVE-2017-7725
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-7725

Количество 2

Количество 2

nvd логотип

CVE-2017-7725

почти 9 лет назад

concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mvg-c6mg-3q63

больше 3 лет назад

Concrete CMS vulnerable to cross-site scripting (XSS)

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-7725

concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.

CVSS3: 6.1
4%
Низкий
почти 9 лет назад
github логотип
GHSA-2mvg-c6mg-3q63

Concrete CMS vulnerable to cross-site scripting (XSS)

CVSS3: 6.1
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу