CVE-2025-29993

Publication date

2025-03-27 09:06:53

Family

jpcert

State

PUBLISHED

Description

The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered URL, such as password reset mail.