A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediacrush
Mediacrush mediacrush |
|
| Vendors & Products |
Mediacrush
Mediacrush mediacrush |
Mon, 01 Dec 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely. | |
| Title | MediaCrush Header paths.py http headers for scripting syntax | |
| Weaknesses | CWE-644 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-01T02:32:05.624Z
Updated: 2025-12-01T02:32:05.624Z
Reserved: 2025-11-30T14:03:43.345Z
Link: CVE-2025-13803
No data.
Status : Awaiting Analysis
Published: 2025-12-01T03:15:46.390
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-13803
No data.