MEDIUM6.1
GHSA-4r4f-jrvw-h727
Feehi CMS host header injection vulnerability
Details
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/feehi/cms
Introduced in:
0No fixed version published yet for feehi/cms (composer). Pin to a known-safe version or switch to an alternative.