First published: Tue Nov 22 2022(Updated: )
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Parallels Remote Application Server | =18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40870 is a vulnerability in the Web Client of Parallels Remote Application Server v18.0 that allows attackers to execute arbitrary commands through a crafted payload injected into the Host header.
CVE-2022-40870 has a severity rating of 8.1 out of 10, indicating a high severity.
CVE-2022-40870 affects Parallels Remote Application Server v18.0.
Host Header Injection is a vulnerability where an attacker can manipulate the Host header to inject a crafted payload.
It is recommended to update to a patched version provided by Parallels Remote Application Server to fix CVE-2022-40870.