134
Views
1
Comments
Host header Injection issue
Question

Hi

our security team raised one security issue.

Name Host Header Injection Status Open Severity Low Exploitability Difficult Function / Target Login Description The application was found to be using HTTP Host Header value without any validation for generating redirection link. Risk / Impact An attacker may be able to exploit host header injection vulnerability by using mechanisms such as web-cache poisoning / password reset poisoning. Evidence Following evidence shows Host Header Injection vulnerability. 

if i change the value of the "Host" header from "XX.com" to "YY.com" and forward the request. Observe that the application successfully redirected to YY.com.


how to resolve this issue?any idea.

2025-10-18 11-13-53
Ramesh subramanian

Hi Arkyadeep Bharadwaj,

please check this link and help for you.

https://www.outsystems.com/forums/discussion/79534/vapt-issue-1-host-header-injection-attack/

Thanks,

Ramesh

Community GuidelinesBe kind and respectful, give credit to the original source of content, and search for duplicates before posting.