Poweradmin v4.3.2 Vulnerability: Host Header Injection in Authentication Flows
Poweradmin v4.3.2 is under investigation for a vulnerability that may allow host header injection in OIDC, SAML, and logout authentication flows, potentially leading to account takeover.
What happened
Poweradmin v4.3.2 appears to use the `HTTP_HOST` request header for constructing callback URLs in its OIDC, SAML, and logout authentication flows without proper validation. This could allow an attacker to inject a malicious host header, leading to a potential full account takeover. The vulnerability is being tracked under GHSA-3735-5339-XFWX.
To assess your exposure, check if you are using Poweradmin v4.3.2. If so, it is recommended to upgrade to a version that includes validation for the `HTTP_HOST` header in authentication flows. The primary sources should be consulted for the most current information and recommended actions.
How 0Day mitigates this
poweradmin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.