Record summary

CVE-2024-23055 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMPlone Docker - Host Header InjectionCVSS 6.1

Plone Docker Official Image 5.2.13 (5221) is vulnerable to Host Header Injection due to improper validation of input by the HOST headers. This can lead to Cross-Site Scripting (XSS) attacks when the malicious Host header value is reflected in the response.

Impact

Remote attackers can execute arbitrary code on the server, potentially leading to full system compromise.

Remediation

Update to the latest version of Plone Docker or apply security patches addressing HOST header validation.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscvecve2024plonexsshost-headerinjection
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Shodan: http.component:"Plone"

Source: ProjectDiscovery

References

4