Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8406 | The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered URL, such as password reset mail. |
Thu, 27 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Mar 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered URL, such as password reset mail. | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-03-27T13:30:08.643Z
Reserved: 2025-03-13T06:16:50.277Z
Link: CVE-2025-29993
Updated: 2025-03-27T13:30:05.307Z
Status : Deferred
Published: 2025-03-27T10:15:14.063
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-29993
No data.
OpenCVE Enrichment
No data.
EUVD