In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade getkirby/cms to version 4.9.4, 5.4.4 or higher.
Affected versions of this package are vulnerable to HTTP Response Splitting via the headers option in the Remote process. An attacker can inject or override HTTP headers in outgoing requests by including newline characters in user-controlled input that is forwarded to the header value. This is only exploitable if custom code, plugins, or integrations pass untrusted input into the headers option of outgoing HTTP requests.