A CRLF injection vulnerability in E-Staff v5.1 allows...
Critical severity
Unreviewed
Published
Jul 25, 2024
to the GitHub Advisory Database
•
Updated Aug 26, 2024
Description
Published by the National Vulnerability Database
Jul 25, 2024
Published to the GitHub Advisory Database
Jul 25, 2024
Last updated
Aug 26, 2024
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.
References