CVE-2025-63828
Backdrop CMS Host Header Injection vulnerability
EPSS 0.19%
Description
Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
How to fix CVE-2025-63828
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Packagist/backdrop/backdrop—no fix listed
Is CVE-2025-63828 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, <= 1.32.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:P |