vendor:
concrete5
by:
John Page a.k.a hyp3rlinx
6.1
CVSS
MEDIUM
Host Header Injection
79
CWE
Product Name: concrete5
Affected Version From: 8.1.2000
Affected Version To: 8.1.2000
Patch Exists: YES
Related CWE: CVE-2017-7725
CPE: concrete5:concrete5:8.1.0
Platforms Tested:
2017
Concrete5 v8.1.0 Host Header Injection
If a user does not specify a 'canonical' URL on installation of concrete5, unauthenticated remote attackers can write to the 'collectionversionblocksoutputcache' table of the MySQL Database, by making HTTP GET request with a poisoned HOST header. Some affected concrete5 webpages can then potentially render arbitrary links that can point to a malicious website.
Mitigation:
Specify a 'canonical' URL during installation to prevent this vulnerability. Patch available from the vendor's website.