CVE-2023-36085
Last modified
CVE-2023-36085 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. This can lead to phishing attacks, malware distribution, and unauthorized access to sensitive resources.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sisqualwfm | Sisqualwfm | >= 7.1.319.103, < 7.1.319.111 |
References
- https://github.com/omershaik0/Handmade_Exploits/tree/main/SISQUALWFM-Host-Header-Injection-CVE-2023-36085Exploit, Third Party Advisory
- https://github.com/omershaik0/Handmade_Exploits/tree/main/SISQUALWFM-Host-Header-Injection-CVE-2023-36085Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-36085?
How severe is CVE-2023-36085?
How do I fix CVE-2023-36085?
Are you affected by CVE-2023-36085?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
