exponentcms / exponent-cms

Content Management, Simple.
exponentcms.org
GNU General Public License v2.0
60 stars 24 forks source link

HTTP Host Header Attack #1544

Closed dumpling-soup closed 3 years ago

dumpling-soup commented 3 years ago

Host value in HTTP header is not checked. Modifying Host header in HTTP request modifies the all links to an arbitrary value. Included example request, result, and location of bug in the source code.

image