ZeroHour

CVE-2025-27632

CVSS 3.1
6.1 medium
EPSS
<1%p15
Published
()
Modified
Description

A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning.

Weakness
CWE-644
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.