CVE-2025-63828

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:backdropcms:backdrop_cms:1.32.1:*:*:*:*:*:*:*

History

24 Nov 2025, 14:02

Type Values Removed Values Added
CPE cpe:2.3:a:backdropcms:backdrop_cms:1.32.1:*:*:*:*:*:*:*
First Time Backdropcms backdrop Cms
Backdropcms
References () https://github.com/mertdurum06/BackdropCms-1.32.1/ - () https://github.com/mertdurum06/BackdropCms-1.32.1/ - Release Notes
References () https://github.com/mertdurum06/BackdropCms-1.32.1/blob/main/backdropcms_exploit.txt - () https://github.com/mertdurum06/BackdropCms-1.32.1/blob/main/backdropcms_exploit.txt - Exploit

19 Nov 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://github.com/mertdurum06/BackdropCms-1.32.1/blob/main/backdropcms_exploit.txt - () https://github.com/mertdurum06/BackdropCms-1.32.1/blob/main/backdropcms_exploit.txt -
CWE CWE-601

18 Nov 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 18:16

Updated : 2025-11-24 14:02


NVD link : CVE-2025-63828

Mitre link : CVE-2025-63828

CVE.ORG link : CVE-2025-63828


JSON object : View

Products Affected

backdropcms

  • backdrop_cms
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')