6.1
CVE-2025-63828
- EPSS 0.03%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 24.11.2025 14:02:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Backdropcms ≫ Backdrop Cms Version1.32.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.065 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.