First published: Mon Aug 09 2021(Updated: )
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | <=1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this host header attack vulnerability is CVE-2021-38290.
CVE-2021-38290 has a severity level of 8.1 (high).
FUEL CMS version 1.5.0 is affected by CVE-2021-38290.
An attacker can exploit CVE-2021-38290 through a man-in-the-middle attack, such as phishing.
Yes, a fix for CVE-2021-38290 is available. Please refer to the references for more information.