Host Header Injection allow HiJack Password Reset Link
Low
C
Concrete CMS
Submitted None
Team Summary
Official summary from Concrete CMS
The issue reported in #59666 and in #226659 is still applicable as originally reported, however it is tracked as an "informative" issue that can be resolved simply with proper webserver configuration or by configuring concrete5 to force a "canonical url".
Actions:
Reported by
gamliel
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate