CVE-2020-28031 describes an HTTP Host header injection vulnerability in eramba versions up to c2.8.1. This flaw allows authenticated users to manipulate the Host header, potentially leading to issues like incorrect PDF generation via wkhtml2pdf. Rated as Medium severity (CVSS 4.3), the vulnerability has a network attack vector and low attack complexity, with a potential impact of low integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.1CPE matchmatch criteria | cpe:2.3:a:eramba:eramba:2.8.1:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.