A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| feehi/cms(Packagist) | 0 | N/A | N/A |
CVSS Metrics