CVE-2019-16645

HIGH

Embedthis GoAhead 2.5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

Exploits (1)

exploitdb WORKING POC
by Ramikan · textremotemultiple
https://www.exploit-db.com/exploits/47439

Scores

CVSS v3 8.6
EPSS 0.1668
EPSS Percentile 95.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Details

CWE
CWE-94
Status published
Products (1)
embedthis/goahead 2.5.0
Published Sep 20, 2019
Tracked Since Feb 18, 2026