Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-4r4f-jrvw-h727: Feehi CMS host header injection vulnerability may allow attacker to spoof a particular header

A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.

ghsa
#vulnerability#git

Feehi CMS host header injection vulnerability may allow attacker to spoof a particular header

Moderate severity GitHub Reviewed Published Sep 15, 2022 • Updated Sep 16, 2022

Related news

CVE-2022-38796

A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.