- Description
- ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP response’s Content-Type, which could lead to several issues depending on the HTTP scenario. For example, we have demonstrated the potential for XSS and arbitrary script source code disclosure in the latest version of mod_security2. This issue is fixed in version 2.9.12.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- modsecurity
CVSS 4.0
- Type
- Secondary
- Base score
- 6.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- Hype score
- Not currently trending
🚨 SECURITY UPDATE 🚨 SUSE has released a patch for #mod_security2 (CVE-2025-54571). This Moderate-rated flaw could lead to XSS or source code disclosure on SLES 12 SP5. Read more: 👉 https://t.co/1XbdUihWDw #Security https://t.co/iEvvlnjWK1
@Cezar_H_Linux
1 Oct 2025
53 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔒 Critical Security Update for SUSE Users Vulnerability CVE-2025-54571 impacts the apache2-mod_security2 package, rated moderate. It involves insufficient return value handling, leading to XSS and source code disclosure risks. Read more: 👉 https://t.co/O6H7bedxeM #Securit
@Cezar_H_Linux
1 Oct 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-54571 Content-Type Bypass Vulnerability in ModSecurity WAF Versions 2.9.11 and Below https://t.co/Pj5tvVYCQe
@VulmonFeeds
6 Aug 2025
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-54571 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override … https://t.co/3fXgviI5i1
@CVEnew
5 Aug 2025
241 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:owasp:modsecurity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DB4F4C3A-DD74-4193-8FC3-61BB563CD089",
"versionEndExcluding": "2.9.12",
"versionStartIncluding": "2.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]