Description
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-5338 Vulnerability (CVE-2006-5338)
WordPress Plugin IgnitionDeck Security Bypass (1.1.6)
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Cross-Site Scripting (6.20.2)
WordPress Plugin KBoard Multiple Vulnerabilities (3.3)
Drupal Core 8.x.x Multiple Cross-Site Scripting Vulnerabilities (8.0.0 - 8.7.14)