A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
- https://www.youtube.com/watch?v=k8dp0FJnSsI
- https://github.com/ARPSyndicate/cvemon