CVE-2022-38796: Medium severity feehi cms vulnerability
Published Sep 14, 2022
·Updated
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
Affected Software
1 affected component
Feehi Feehi CMS=2.1.1
Event History
Sep 14, 2022
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-38796?
CVE-2022-38796 is considered a medium severity vulnerability due to its potential impact on authentication processes.
2
How do I fix CVE-2022-38796?
To fix CVE-2022-38796, upgrade Feehi CMS to the latest version or implement proper validation of host headers.
3
What systems are impacted by CVE-2022-38796?
CVE-2022-38796 affects Feehi CMS version 2.1.1.
4
What type of attack can be executed using CVE-2022-38796?
CVE-2022-38796 can be exploited to spoof headers, potentially leading to unauthorized access during password resets.
5
Is there a workaround for CVE-2022-38796?
A possible workaround for CVE-2022-38796 includes disabling any functionality that allows user-controlled host header manipulation.