Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
References
Configurations
History
24 Nov 2025, 14:02
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:backdropcms:backdrop_cms:1.32.1:*:*:*:*:*:*:* | |
| First Time |
Backdropcms backdrop Cms
Backdropcms |
|
| References | () https://github.com/mertdurum06/BackdropCms-1.32.1/ - Release Notes | |
| References | () https://github.com/mertdurum06/BackdropCms-1.32.1/blob/main/backdropcms_exploit.txt - Exploit |
19 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| References | () https://github.com/mertdurum06/BackdropCms-1.32.1/blob/main/backdropcms_exploit.txt - | |
| CWE | CWE-601 |
18 Nov 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-18 18:16
Updated : 2025-11-24 14:02
NVD link : CVE-2025-63828
Mitre link : CVE-2025-63828
CVE.ORG link : CVE-2025-63828
JSON object : View
Products Affected
backdropcms
- backdrop_cms
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
