Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25625

Опубликовано: 19 фев. 2024
Источник: nvd
CVSS3: 8.1
CVSS3: 9.3
EPSS Низкий

Описание

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in pimcore/admin-ui-classic-bundle prior to version 1.3.4. The vulnerability involves a Host Header Injection in the invitationLinkAction function of the UserController, specifically in the way $loginUrl trusts user input. The host header from incoming HTTP requests is used unsafely when generating URLs. An attacker can manipulate the HTTP host header in requests to the /admin/user/invitationlink endpoint, resulting in the generation of URLs with the attacker's domain. In fact, if a host header is injected in the POST request, the $loginURL parameter is constructed with this unvalidated host header. It is then used to send an invitation email to the provided user. This vulnerability can be used to perform phishing attacks by making the URLs in the invitation links emails point to an attacker-controlled domain. Version 1.3.4 contains a patch for the vulnerabili

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pimcore:admin_classic_bundle:*:*:*:*:*:pimcore:*:*
Версия до 1.3.4 (исключая)

EPSS

Процентиль: 4%
0.0002
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS3

Дефекты

CWE-74
CWE-74

Связанные уязвимости

CVSS3: 8.1
github
почти 2 года назад

Pimcore Host Header Injection in user invitation link

EPSS

Процентиль: 4%
0.0002
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS3

Дефекты

CWE-74
CWE-74