{"id":"CVE-2017-7725","details":"concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a \"canonical\" URL on installation of concrete5 using the \"Advanced Options\" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.","aliases":["GHSA-2mvg-c6mg-3q63"],"modified":"2026-07-08T11:36:25.187020Z","published":"2017-04-13T17:59:00.700Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97649"},{"type":"EVIDENCE","url":"http://hyp3rlinx.altervista.org/advisories/CONCRETE5-v8.1.0-HOST-HEADER-INJECTION.txt"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/148300"},{"type":"EVIDENCE","url":"https://packetstormsecurity.com/files/142145/concrete5-8.1.0-Host-Header-Injection.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/41885/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/concretecms/concretecms","events":[{"introduced":"4ec6574c0ef509ccb37357756bb985d35562735e"},{"last_affected":"4ec6574c0ef509ccb37357756bb985d35562735e"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:concretecms:concrete_cms:8.1.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.1.0"},{"last_affected":"8.1.0"}]}}],"versions":["8.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7725.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}