Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-18T17:28:17.080Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63828
No data.
Status : Received
Published: 2025-11-18T18:16:13.753
Modified: 2025-11-18T18:16:13.753
Link: CVE-2025-63828
No data.
OpenCVE Enrichment
No data.