6.5
CVSSv2

CVE-2018-6889

Published: 12/02/2018 Updated: 06/03/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.

Vulnerable Product Search on Vulmon Subscribe to Product

typesettercms typesetter 5.1

Exploits

​# Exploit Title: TypeSetter CMS 51 Host Header Injection # Date: 10-02-2018 # Exploit Author: Navina Asrani # Contact: twittercom/NavinaSanjay # Website: securitywarrior9blogspotin/ # Vendor Homepage: wwwtypesettercmscom/ # Version: 51 # CVE : NA # Category: Webapp CMS 1 Description The application allows illegi ...