CVE-2025-28096 | OneNav 1.1.0 Header server-side request forgery
A vulnerability classified as critical has been found in OneNav 1.1.0. Affected is an unknown function of the component Header Handler. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2025-28096. It is possible to launch the attack remotely. There is no exploit available.