CVE-2019-16645
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.
- Affected products
- Goahead
- Embedthis Goahead
- = 2.5.0
- Fix
- Available
- CVSS 3.1
- 8.6 HIGH
- EPSS
- 8.2% (95th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2019-09-20
CVE-2019-16645 at NVD
3 known exploits for CVE-2019-16645
Proof-of-concept code and exploit modules indexed by Sploitus