Логотип exploitDog
bind:CVE-2022-22691
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-22691

Количество 2

Количество 2

nvd логотип

CVE-2022-22691

около 4 лет назад

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. A related vulnerability (CVE-2022-22690) could allow this flaw to become persistent so that all password reset URLs are affected persistently following a successful attack. See the AppCheck advisory for further information and associated caveats.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-r8pr-83cc-ccv7

около 4 лет назад

Umbraco Persistent Password Reset Poison

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-22691

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. A related vulnerability (CVE-2022-22690) could allow this flaw to become persistent so that all password reset URLs are affected persistently following a successful attack. See the AppCheck advisory for further information and associated caveats.

CVSS3: 6.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-r8pr-83cc-ccv7

Umbraco Persistent Password Reset Poison

CVSS3: 7.4
0%
Низкий
около 4 лет назад

Уязвимостей на страницу