cve/2021/CVE-2021-25994.md
2025-09-29 21:09:30 +02:00

1023 B
Raw Blame History

CVE-2021-25994

Description

In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victims password and successfully take over their account.

POC

Reference

Github

No PoCs found on GitHub currently.