openITCOCKPIT up to and including 3.7.2 allows remote malicious users to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
it-novum openitcockpit |