A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2024-07-25. NVD baseline CVSS 5.4; sources differ by 4.4.
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.
July 25, 2024
November 21, 2024
See which npm, PyPI, Go, and Maven packages are affected by CVE-2024-40324
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.