CVE-2025-63828: Medium severity Backdrop CMS vulnerability
Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63828?
CVE-2025-63828 is considered a high severity vulnerability due to its potential for session hijacking and redirecting users to malicious domains.
How do I fix CVE-2025-63828?
To fix CVE-2025-63828, upgrade Backdrop CMS to version 1.32.1 or later to mitigate the host header injection vulnerability.
What is the impact of exploiting CVE-2025-63828?
Exploitation of CVE-2025-63828 can lead to unauthorized access and session hijacking via cookie injection.
Which versions of Backdrop CMS are affected by CVE-2025-63828?
CVE-2025-63828 affects Backdrop CMS version 1.32.1 and earlier versions up to and including 1.32.0.
Can CVE-2025-63828 be exploited remotely?
Yes, CVE-2025-63828 can be exploited remotely by attackers who manipulate the Host header in password reset requests.