PT-2021-3936 · Unknown · Exponent Cms
Dumpling-Soup
·
Published
2021-08-10
·
Updated
2021-08-23
·
CVE-2021-38751
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ExponentCMS versions 2.6 and below
Description
A HTTP Host header attack exists in ExponentCMS, allowing a modified HTTP header to change links on the webpage to an arbitrary value. This can lead to a possible attack vector for Man-in-the-Middle (MITM) attacks. The issue is related to a lack of output encoding or escaping mechanism in the system, which can be exploited by a remote attacker to impact the integrity of protected information by modifying the HTTP header.
Recommendations
For ExponentCMS versions 2.6 and below, consider disabling access to the /exponent constants.php file until a patch is available. As a temporary workaround, restrict the modification of HTTP headers to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exponent Cms