PT-2025-31395 · Heimdal · Heimdal

Jfoz1010

+1

·

Publicado

2025-07-30

·

Atualizado

2026-04-02

·

CVE-2025-50578

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions heimdall version 2.6.3-ls307
Description The application does not properly validate user-supplied HTTP headers, specifically X-Forwarded-Host and Referer. This allows for Host Header Injection and Open Redirect attacks. An unauthenticated remote attacker can manipulate these headers to load external resources from attacker-controlled domains and redirect users, potentially enabling phishing, UI redress, and session theft. The issue is due to insufficient validation of untrusted input, impacting the application’s integrity and trustworthiness.
Recommendations Apply input validation and sanitization to the X-Forwarded-Host and Referer HTTP headers to prevent manipulation.

Exploit

Correção

RCE

Open Redirect

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-50578

Produtos afetados

Heimdal