{ "schema_version": "1.4.0", "id": "GHSA-7hhp-9v6r-9h4x", "modified": "2022-05-24T19:10:27Z", "published": "2022-05-24T19:10:27Z", "aliases": [ "CVE-2021-38290" ], "details": "A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38290" }, { "type": "WEB", "url": "https://github.com/daylightstudio/FUEL-CMS/issues/580" }, { "type": "WEB", "url": "https://github.com/daylightstudio/FUEL-CMS/commit/8a0d88ad6869623c90e24b3b2ea33352049d39a7" } ], "database_specific": { "cwe_ids": [ "CWE-74" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-08-09T11:15:00Z" } }