A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can manipulate the Host header to send malicious reset links, enabling phishing attacks or account takeover.
References
Configurations
No configuration.
History
16 Oct 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
16 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-16 15:15
Updated : 2025-10-16 19:15
NVD link : CVE-2025-61543
Mitre link : CVE-2025-61543
CVE.ORG link : CVE-2025-61543
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
