Remote Header Injection Vulnerability in Anchor CMS by Anchor
CVE-2014-9182

Currently unrated

Key Information:

Vendor

Anchorcms

Vendor
CVE Published:
2 December 2014

What is CVE-2014-9182?

In Anchor CMS versions 0.9.2 and earlier, a vulnerability exists in models/comment.php that allows remote attackers to inject arbitrary headers into mail messages by manipulating the Host: header. This flaw can potentially be exploited for various types of attacks, including the ability to send malicious payloads or spoof email communications, thereby compromising the integrity and confidentiality of communications generated by the CMS.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.