Логотип exploitDog
bind:CVE-2025-61136
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-61136

Количество 2

Количество 2

nvd логотип

CVE-2025-61136

4 месяца назад

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3pjg-h7vp-42p9

4 месяца назад

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-61136

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3pjg-h7vp-42p9

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.

CVSS3: 7.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу