Host Header Injection Vulnerability in Feehi CMS by Feehi
CVE-2022-38796
6.1MEDIUM
What is CVE-2022-38796?
A host header injection flaw in Feehi CMS version 2.1.1 can allow attackers to manipulate the Host header, potentially enabling them to spoof requests. This vulnerability can be particularly dangerous as it may lead to the exploitation of password reset functionality, giving malicious actors the opportunity to gain unauthorized access to user accounts.
