CVE-2021-25994
EUVD-2022-056503.01.2022, 07:15
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| userfrosting | userfrosting | 0.3.1 ≤ 𝑥 < 4.6.3 |
𝑥
= Vulnerable software versions
References