CVE Database
/

CVE-2025-63828

Back to search

CVE-2025-63828

Published: Nov 18, 2025

Modified: Nov 19, 2025

PUBLISHED

Description

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.

VendorProductVersions

n/a

n/a

affected
n/a

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now