CVE-2017-7725: XSS
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.
Other sources
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header. This is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
concrete5to a version that resolves this vulnerability.Fixed in 8.1.0 - Configuration
During concrete5 installation, use the "Advanced Options" settings to define a canonical URL; this prevents incorrect trust in the HTTP Host header during caching when no canonical URL is set.
concrete5 Advanced Options (canonical URL) = Define a canonical URL during installation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7725?
CVE-2017-7725 is considered to be of medium severity due to the potential for remote header injection attacks.
How do I fix CVE-2017-7725?
To fix CVE-2017-7725, ensure that a canonical URL is defined during the installation of concrete5 in the Advanced Options settings.
What versions of Concrete5 are affected by CVE-2017-7725?
CVE-2017-7725 affects Concrete5 version 8.1.0 and earlier.
What type of attack can be performed using CVE-2017-7725?
CVE-2017-7725 allows remote attackers to exploit header injection vulnerabilities via manipulated Host headers.
How can I verify if my Concrete5 installation is vulnerable to CVE-2017-7725?
To verify if your Concrete5 installation is vulnerable, check if the system is running version 8.1.0 or earlier and whether a canonical URL has been set.