Sploitus

CVE-2019-16645

3 known exploits for CVE-2019-16645

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

Affected products
Goahead
Embedthis Goahead
= 2.5.0
Fix
Available
CVSS 3.1
8.6 HIGH
EPSS
8.2% (95th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2019-09-20
CVE-2019-16645 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2019-16645

Proof-of-concept code and exploit modules indexed by Sploitus