CVE-2020-25901: Spiceworks
Medium severity, CVSS 6.1. EPSS: 5.1% chance of exploitation in the next 30 days.
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
Affected products
- Spiceworks Spiceworks: version 7.5.7.0 only
Published 2020-12-18. Last modified 2026-06-17.