216.73.217.22

CVE-2024-42914

· Published 23/08/2024 19:15 · Modified 26/08/2024 17:35

Labels: CVE-2024-42914 2024-08-23CVE-2024-42914CWE-74[email protected]

Essential information

Published
23/08/2024 19:15
Modified
26/08/2024 17:35
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References