CVE-2025-23001

A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. NOTE: the Supplier's position is that the end user is supposed to edit the NGINX configuration template to set server_name (with this setting, Host header injection cannot occur).
Configurations

No configuration.

History

21 Feb 2025, 17:15

Type Values Removed Values Added
CWE CWE-644
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

21 Feb 2025, 05:15

Type Values Removed Values Added
Summary (en) A Host Header Injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. (en) A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. NOTE: the Supplier's position is that the end user is supposed to edit the NGINX configuration template to set server_name (with this setting, Host header injection cannot occur).
References
  • () https://blog.ctfd.io/ctfd-3-7-6/ -

18 Feb 2025, 19:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : unknown

03 Feb 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
Summary
  • (es) Existe una vulnerabilidad de inyección de encabezado de host en CTFd 3.7.5, debido a que la aplicación no puede validar o desinfectar correctamente el encabezado de host. Un atacante puede manipular el encabezado de host en solicitudes HTTP, lo que puede provocar ataques de phishing, restablecimiento de contraseñas o envenenamiento de caché.
CWE CWE-89

31 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-31 17:15

Updated : 2025-02-21 17:15


NVD link : CVE-2025-23001

Mitre link : CVE-2025-23001

CVE.ORG link : CVE-2025-23001


JSON object : View

Products Affected

No product.

CWE
CWE-644

Improper Neutralization of HTTP Headers for Scripting Syntax