Croogo Host Header Injection Vulnerability

Vulnerability

A host header injection vulnerability has been identified in Croogo version 3.0.2. This issue allows attackers to manipulate the host header through the feed.rss component.

Impact

Exploitation of this vulnerability could lead to host header injection, which may be used for various attacks such as web cache poisoning or open redirect vulnerabilities.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
9.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.