Loading HuntDB...

Host Header Injection allow HiJack Password Reset Link

Low
C
Concrete CMS
Submitted None

Team Summary

Official summary from Concrete CMS

The issue reported in #59666 and in #226659 is still applicable as originally reported, however it is tracked as an "informative" issue that can be resolved simply with proper webserver configuration or by configuring concrete5 to force a "canonical url".

Reported by gamliel

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted