CVE-2020-25901: Spiceworks

Medium severity, CVSS 6.1. EPSS: 5.1% chance of exploitation in the next 30 days.

Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.

Affected products

Published 2020-12-18. Last modified 2026-06-17.