An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://ibb.co/DpxHpz9 | exploit |
https://ibb.co/T0fhLwR | exploit |
https://github.com/shenhav12/CVE-2024-25170-Mezzanine-v6.0.0 | third party advisory |