CVE-2024-25170

CRITICAL

Mezzanine 6.0.0 - Incorrect Authorization via Host Header Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-25170. PoCs published by shenhav12.

AI-analyzed exploit summary This repository contains only a README describing an incorrect access control vulnerability in Mezzanine CMS v6.0.0 via Host Header manipulation. No actual exploit code or PoC is provided.

Description

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

Exploits (1)

nomisec STUB
by shenhav12 · poc
https://github.com/shenhav12/CVE-2024-25170-Mezzanine-v6.0.0

This repository contains only a README describing an incorrect access control vulnerability in Mezzanine CMS v6.0.0 via Host Header manipulation. No actual exploit code or PoC is provided.

Classification
Stub 80%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: Mezzanine CMS v6.0.0
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 9.1
EPSS 0.0179
EPSS Percentile 83.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
jupo/mezzanine 6.0.0
pypi/Mezzanine 0PyPI
Published Feb 28, 2024
Tracked Since Feb 18, 2026