The following table lists the changes that have been made to the
CVE-2025-23001 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jan. 31, 2025
Action Type Old Value New Value Added Description A Host Header Injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. Added Reference https://codetoanbug.com/poc-cve-2025-23001-ctfd-english/ Added Reference https://github.com/CTFd/CTFd