An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://securitywarrior9.blogspot.in/2018/02/host-header-injection-type-setter-cms-51.html | third party advisory exploit |
https://www.exploit-db.com/exploits/44028/ | third party advisory vdb entry exploit |