Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') (CWE-113)
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.
Feedly found the first article mentioning CVE-2018-16979. See article
EPSS Score was set to: 0.12% (Percentile: 45.5%)