Alfasado PowerCMS
cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*
- <= 6.6
- <= 5.27
- <= 4.58
A vulnerability in Alfasado PowerCMS in versions through 6.6, 5.27, and 4.58 allows HTTP header injection. This issue can be exploited to manipulate URLs in emails sent by the application, such as password reset messages.
Exploitation of this vulnerability can lead to HTTP header injection, allowing for the manipulation of email content and URLs, potentially causing phishing or social engineering attacks.
Users are advised to update PowerCMS to the latest version. PowerCMS 6.61, 5.28, and 4.59 have addressed this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.