CVE-2024-23055
Plone Docker - Host Header Injection
Record summary
CVE-2024-23055 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMPlone Docker - Host Header InjectionCVSS 6.1
Plone Docker Official Image 5.2.13 (5221) is vulnerable to Host Header Injection due to improper validation of input by the HOST headers. This can lead to Cross-Site Scripting (XSS) attacks when the malicious Host header value is reflected in the response.
Impact
Remote attackers can execute arbitrary code on the server, potentially leading to full system compromise.
Remediation
Update to the latest version of Plone Docker or apply security patches addressing HOST header validation.
Source: ProjectDiscovery