An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
References
Configurations
No configuration.
History
22 Apr 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-444 | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
References | () https://medium.com/@christbowel6/cve-2024-29643-host-header-injection-in-croogo-v3-0-2-0aded525f574 - |
21 Apr 2025, 14:23
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-18 15:15
Updated : 2025-04-22 15:16
NVD link : CVE-2024-29643
Mitre link : CVE-2024-29643
CVE.ORG link : CVE-2024-29643
JSON object : View
Products Affected
No product.
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')