First published: Thu Dec 20 2018(Updated: )
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getkirby Kirby | =2.5.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-16627.
The title of this vulnerability is 'panel/login in Kirby v2.5.12 allows Host header injection via the forget password feature.'
The severity of CVE-2018-16627 is medium, with a severity value of 6.1.
Kirby version 2.5.12 is affected by CVE-2018-16627.
To fix CVE-2018-16627, update to a version of Kirby that is not affected by this vulnerability.