Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5gx-365m-gfgx

Опубликовано: 19 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.5

Описание

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.

EPSS

Процентиль: 12%
0.00039
Низкий

8.6 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.

EPSS

Процентиль: 12%
0.00039
Низкий

8.6 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-640