HTTP Header Injection Vulnerability in PowerCMS by PowerCMS Inc.
CVE-2025-29993
5.3MEDIUM
What is CVE-2025-29993?
PowerCMS versions prior to the latest release are susceptible to HTTP header injection, which can be exploited to manipulate the content of emails sent by the application. This flaw allows malicious actors to craft a tampered URL, potentially executing unintended actions such as generating password reset emails that direct users to malicious locations. Prompt patching is recommended to mitigate the associated risks.
Affected Version(s)
PowerCMS 4.x series 4.58 and earlier
PowerCMS 5.x series 5.27 and earlier
PowerCMS 6.x series 6.6 and earlier
