Loading
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.
Use CWE-94, Embedthis vendor hub and Goahead product page to widen CVE-2019-16645 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-41615, CVE-2021-43298 and CVE-2021-42342 for nearby disclosures in the same product family.