Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8pr-83cc-ccv7

Опубликовано: 21 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Umbraco Persistent Password Reset Poison

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. A related vulnerability (CVE-2022-22690) could allow this flaw to become persistent so that all password reset URLs are affected persistently following a successful attack. See the AppCheck advisory for further information and associated caveats.

Пакеты

Наименование

Umbraco.Cms.Core

nuget
Затронутые версииВерсия исправления

< 9.2.0

9.2.0

EPSS

Процентиль: 49%
0.00255
Низкий

7.4 High

CVSS3

Дефекты

CWE-444
CWE-640

Связанные уязвимости

CVSS3: 6.8
nvd
около 4 лет назад

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. A related vulnerability (CVE-2022-22690) could allow this flaw to become persistent so that all password reset URLs are affected persistently following a successful attack. See the AppCheck advisory for further information and associated caveats.

EPSS

Процентиль: 49%
0.00255
Низкий

7.4 High

CVSS3

Дефекты

CWE-444
CWE-640