A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 |
Fri, 24 Oct 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-644 |
Tue, 25 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Mar 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning. | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Hitachi Energy
Published: 2025-03-25T12:37:30.114Z
Updated: 2025-10-24T12:10:40.967Z
Reserved: 2025-03-04T11:40:47.755Z
Link: CVE-2025-27632
Updated: 2025-03-25T13:10:34.321Z
Status : Awaiting Analysis
Published: 2025-03-25T13:15:41.090
Modified: 2025-10-24T13:15:46.917
Link: CVE-2025-27632
No data.