CVE-2025-23001
CVE-2025-23001
Título es
CVE-2025-23001
Vie, 31/01/2025 – 17:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-23001
Descripción en
A Host Header Injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning.
31/01/2025
31/01/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off