Unsafe usage of Host HTTP header in Concrete5 version 5.7.3.1
C
Concrete CMS
Submitted None
Actions:
Reported by
egix
Vulnerability Details
Technical details and impact analysis
Concrete5 is affected by a design issue related to the Host HTTP header. Such header is being used to define the base URL for the application. Since the Host header can be arbitrarily manipulated by an attacker, this can have some security impacts.
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Violation of Secure Design Principles