Security Advisory

CVE-2025-27913

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-03-10 00:00:00
Last updated 2025-03-11 02:52:25
Assigner mitre
CVSS score 2.1
State PUBLISHED

Description

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.