CVE-2022-38796 - Feehi CMS 2.1.1 Host Header Injection
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header.
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header.
The plugin does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.