CVE-2018-16627: Medium severity getkirby vulnerability
Published Dec 20, 2018
·Updated
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
Affected Software
1 affected component
getkirby Kirby=2.5.12
Event History
Dec 20, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-16627.
2
What is the title of this vulnerability?
The title of this vulnerability is 'panel/login in Kirby v2.5.12 allows Host header injection via the forget password feature.'
3
What is the severity of CVE-2018-16627?
The severity of CVE-2018-16627 is medium, with a severity value of 6.1.
4
What software versions are affected by CVE-2018-16627?
Kirby version 2.5.12 is affected by CVE-2018-16627.
5
How can I fix CVE-2018-16627?
To fix CVE-2018-16627, update to a version of Kirby that is not affected by this vulnerability.