PT-2022-11787 · Compass Plus · Compass Plus Tranzware Online Fimi Web Interface Fimi

Published

2022-02-14

·

Updated

2022-02-23

·

CVE-2021-43106

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) version 5.3.33.3 F38 Compass Plus TranzWare Online FIMI Web Interface FIMI version 4.2.19.4 25
Description A Header Injection issue exists, allowing manipulation of the HTTP host header, which can cause the application to behave unexpectedly. The server trusts the Host header without proper validation or escaping, enabling an attacker to redirect users to a malicious domain or webpage, potentially leading to further attacks.
Recommendations For version 5.3.33.3 F38, consider implementing proper validation and escaping of the Host header to prevent manipulation. For version 4.2.19.4 25, restrict access to the HTTP host header or disable it until a patch is available. As a temporary workaround, consider restricting the Host header in the HTTP request to minimize the risk of exploitation.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43106

Affected Products

Compass Plus Tranzware Online Fimi Web Interface Fimi