A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
{
"cwe_ids": [
"CWE-74"
],
"github_reviewed": true,
"github_reviewed_at": "2022-09-16T17:07:41Z",
"nvd_published_at": "2022-09-14T15:15:00Z",
"severity": "MODERATE"
}