Логотип exploitDog
bind:CVE-2020-27687
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-27687

Количество 2

Количество 2

nvd логотип

CVE-2020-27687

около 5 лет назад

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-gxgw-6q4v-hcj8

больше 3 лет назад

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-27687

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.

CVSS3: 8.8
0%
Низкий
около 5 лет назад
github логотип
GHSA-gxgw-6q4v-hcj8

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу