Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backdropcms
Backdropcms backdrop Cms |
|
| Vendors & Products |
Backdropcms
Backdropcms backdrop Cms |
Wed, 19 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
cvssV3_1
|
Tue, 18 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-18T00:00:00.000Z
Updated: 2025-11-19T16:50:10.716Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63828
Updated: 2025-11-19T16:30:08.268Z
Status : Awaiting Analysis
Published: 2025-11-18T18:16:13.753
Modified: 2025-11-19T19:14:59.327
Link: CVE-2025-63828
No data.