PcVue WebClient
cpe:2.3:a:pcvuesolutions:pcvue:*:*:*:*:*:*:*
- >= 15.0.0, <= 16.3.3
A vulnerability allowing HTTP Host header injection has been identified in the WebClient and WebScheduler applications of PcVue, affecting versions 15.0.0 through 16.3.3. This vulnerability allows remote attackers to inject harmful payloads that manipulate server-side behavior. The issue is present in the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback, and /Authentication/Logout.
Exploitation of this vulnerability could lead to unauthorized manipulation of server-side behavior, potentially allowing for further attacks or exploitation of additional vulnerabilities.
Users can upgrade to PcVue version 16.3.4 or 15.2.14 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.