8.8
CVSSv3

CVE-2023-38877

Published: 28/09/2023 Updated: 02/10/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This allows an malicious user to reset other users' passwords.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

economizzer economizzer april_2023

economizzer economizzer 0.9