Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6c2c-797q-5r9x

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.

EPSS

Процентиль: 17%
0.00256
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-350

Связанные уязвимости

CVSS3: 7.5
nvd
15 дней назад

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.

EPSS

Процентиль: 17%
0.00256
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-350