Loading HuntDB...

Unsafe usage of Host HTTP header in Concrete5 version 5.7.3.1

C
Concrete CMS
Submitted None
Reported by egix

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Concrete5 is affected by a design issue related to the Host HTTP header. Such header is being used to define the base URL for the application. Since the Host header can be arbitrarily manipulated by an attacker, this can have some security impacts.

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Violation of Secure Design Principles