vendor:
Typesetter CMS
by:
Navina Asrani
CVSS
HIGH
Host Header Injection
NA
CWE
Product Name: Typesetter CMS
Affected Version From: 5.1
Affected Version To: 5.1
Patch Exists: NO
Related CWE: NA
CPE: NA
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2018
TypeSetter CMS 5.1 Host Header Injection
The application allows illegitimate host header manipulation and leads to aribtary web page re-direction. This can also lead to severe attacks such as password reset or web cache poisoning. A attacker can perform application modification to perform advanced attacks as as password reset/ cache poisoning etc.
Mitigation:
To Mitigate host header injections allows only a white-list of allowed host names.