diff --git a/src/webui/abstractwebapplication.cpp b/src/webui/abstractwebapplication.cpp index 786f3d954..4428328f7 100644 --- a/src/webui/abstractwebapplication.cpp +++ b/src/webui/abstractwebapplication.cpp @@ -420,8 +420,7 @@ bool AbstractWebApplication::isCrossSiteRequest(const Http::Request &request) co bool AbstractWebApplication::validateHostHeader(const Http::Request &request, const Http::Environment &env, const QStringList &domains) const { - const QUrl hostHeader = QUrl::fromUserInput( - request.headers.value(Http::HEADER_X_FORWARDED_HOST, request.headers.value(Http::HEADER_HOST))); + const QUrl hostHeader = QUrl::fromUserInput(request.headers.value(Http::HEADER_HOST)); // (if present) try matching host header's port with local port const int requestPort = hostHeader.port();