Security Advisory

CVE-2021-38751

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-08-16 13:53:19
Last updated 2024-08-04 01:51:20
Assigner mitre
State PUBLISHED

Description

A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM.