CVE-2025-62428
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-16

Last updated on: 2025-10-21

Assigner: GitHub, Inc.

Description
Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoints. It allows an attacker to manipulate the Host header in HTTP requests to generate malicious email confirmation links. These links can redirect users to attacker-controlled domains. This vulnerability affects all users relying on email confirmation for account registration or verification. This vulnerability is fixed in 1.2.5-alpha-patch.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-16
Last Modified
2025-10-21
Generated
2026-06-16
AI Q&A
2025-10-16
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
drawing-captcha drawing-captcha-app 1.2.5-alpha-patch
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a Host Header Injection in the /register and /confirm-email endpoints of the Drawing-Captcha APP. It allows an attacker to manipulate the Host header in HTTP requests to generate malicious email confirmation links that redirect users to attacker-controlled domains.

Impact Analysis

The vulnerability can impact users by allowing attackers to send malicious email confirmation links that redirect users to attacker-controlled domains, potentially leading to phishing attacks or unauthorized access during account registration or verification.

Mitigation Strategies

The immediate step to mitigate this vulnerability is to update the Drawing-Captcha APP to version 1.2.5-alpha-patch or later, where the Host Header Injection vulnerability has been fixed.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-62428. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart