Описание
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.3.1 (включая) до 4.6.3 (исключая)
cpe:2.3:a:userfrosting:userfrosting:*:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01758
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-74
CWE-74
Связанные уязвимости
EPSS
Процентиль: 82%
0.01758
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-74
CWE-74