Host Header Injection Vulnerability in Feehi CMS by Feehi
CVE-2022-38796

6.1MEDIUM

Key Information:

Vendor

Feehi

Status
Vendor
CVE Published:
14 September 2022

What is CVE-2022-38796?

A host header injection flaw in Feehi CMS version 2.1.1 can allow attackers to manipulate the Host header, potentially enabling them to spoof requests. This vulnerability can be particularly dangerous as it may lead to the exploitation of password reset functionality, giving malicious actors the opportunity to gain unauthorized access to user accounts.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.