CVE-2019-16645: Code Injection
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/logoffpage.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16645?
The severity of CVE-2019-16645 is high with a CVSS score of 8.6.
What is the vulnerability in Embedthis GoAhead 2.5.0?
The vulnerability in Embedthis GoAhead 2.5.0 is a host header injection vulnerability.
Which pages are affected by the vulnerability in Embedthis GoAhead 2.5.0?
The pages such as goform/login and config/log_off_page.htm are affected by the vulnerability.
How can the host header injection vulnerability in Embedthis GoAhead 2.5.0 be exploited?
The vulnerability can be exploited by creating links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker, potentially leading to phishing attacks.
Is there a fix available for CVE-2019-16645?
At the moment, there is no fix or patch available for CVE-2019-16645. It is recommended to apply security best practices and monitor for any updates from the vendor.