Headline
GHSA-4r4f-jrvw-h727: Feehi CMS host header injection vulnerability may allow attacker to spoof a particular header
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
Feehi CMS host header injection vulnerability may allow attacker to spoof a particular header
Moderate severity GitHub Reviewed Published Sep 15, 2022 • Updated Sep 16, 2022
Related news
CVE-2022-38796
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.