A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.
CRLF
E-Staff
E-Staff 5.1
HTTP headers
Remote
Potential for arbitrary header injection, cache poisoning, and session hijacking, cross-site scripting (XSS), and other exploits.
- Aleksey Vistorobskiy
An attacker can insert CRLF characters into input fields, manipulating HTTP headers. For example, injecting CRLF into HTTP headers can result in HTTP response splitting