{"id":"CVE-2017-7725","aliases":["GHSA-2mvg-c6mg-3q63"],"url":"https://o3.security/vulnerability/CVE-2017-7725","summary":"Concrete CMS vulnerable to cross-site scripting (XSS)","details":"concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a \"canonical\" URL on installation of concrete5 using the \"Advanced Options\" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.","published":"2017-04-13T17:59:00.700Z","modified":"2026-07-08T11:36:25.187020Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.02752,"percentile":0.85034,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":5,"affectedPackages":[{"ecosystem":"Packagist","name":"concrete5/concrete5","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97649"},{"type":"EVIDENCE","url":"http://hyp3rlinx.altervista.org/advisories/CONCRETE5-v8.1.0-HOST-HEADER-INJECTION.txt"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/148300"},{"type":"EVIDENCE","url":"https://packetstormsecurity.com/files/142145/concrete5-8.1.0-Host-Header-Injection.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/41885/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:36:25.187020Z"}}