concrete5 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7725 - Vulnerability Database

concrete5 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7725

Medium
Reference: CVE-2017-7725
Title: concrete5 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching if the administrator did not define a quotcanonicalquot URL on installation of concrete5 using the quotAdvanced Optionsquot settings. Remote attackers can make a GET request with any domain name in the Host header this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors potentially an XSS vector.