CVE-2021-25994
03.01.2022, 07:15
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the forgot password functionality to reset the victims password and successfully take over their account.
Vendor | Product | Version |
---|---|---|
userfrosting | userfrosting | 0.3.1 ≤ 𝑥 < 4.6.3 |
𝑥
= Vulnerable software versions
References