CVE-2021-43106
Last modified
CVE-2021-43106 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. This is due to that the server implicitly trusts the Host header, and fails to validate or escape it properly. An attacker can use this input to redirect target users to a malicious domain/web page. This would result in expanding the potential to further attacks and malicious actions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Compassplus | Tranzware Online | 5.3.33.3_f38 |
| Compassplus | Tranzware Online Financial Institution Maintenance Interface | 4.2.19.4.25 |
References
- https://github.com/IthacaLabs/CompassPlus/tree/main/TranzWare%20Online%20FIMI_Version%204.2.19.4%2025_HHIExploit, Third Party Advisory
- https://github.com/IthacaLabs/CompassPlus/tree/main/TranzWare%20Online%20FIMI_Version%204.2.19.4%2025_HHIExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43106?
How severe is CVE-2021-43106?
How do I fix CVE-2021-43106?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-4310A vulnerability was found in 01-Scripts 01-Artikelsystem. It…6.1
- CVE-2021-43100A File Upload vulnerability exists in bbs 5.3 is via TopicMa…7.2
- CVE-2021-43101A File Upload vulnerability exists in bbs 5.3 is via Members…7.2
- CVE-2021-43102A File Upload vulnerability exists in bbs 5.3 is via HelpMan…7.2
- CVE-2021-43103A File Upload vulnerability exists in bbs 5.3 is via ForumMa…7.2
- CVE-2021-43105A vulnerability in the bailiwick checking function in Techni…4.3
- CVE-2021-43109An SQL Injection vulnerability exits in PuneethReddyHC onlin…7.5
- CVE-2021-4311A vulnerability classified as problematic was found in Talen…9.8
- CVE-2021-43110An Access Conrol vulnerability exists in PuneethReddyHC onli…9.8
- CVE-2021-43113iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 al…9.8
- CVE-2021-43114FORT Validator versions prior to 1.5.2 will crash if an RPKI…7.5
- CVE-2021-43116An Access Control vulnerability exists in Nacos 2.0.3 in the…8.8
Are you affected by CVE-2021-43106?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
