A Host Header Injection vulnerability exists in CTFd 3.7...
Moderate severity
Unreviewed
Published
Jan 31, 2025
to the GitHub Advisory Database
•
Updated Feb 21, 2025
Description
Published by the National Vulnerability Database
Jan 31, 2025
Published to the GitHub Advisory Database
Jan 31, 2025
Last updated
Feb 21, 2025
A Host Header Injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning.
References