-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability occurs in the password reset email generation endpoint (/admin/actions/users/send-password-reset-email). The UsersController's sendPasswordResetEmailAction is responsible for processing reset requests. It improperly trusts the X-Forwarded-Host header when constructing password reset URLs, allowing attackers to poison the link's domain. This matches the described attack vector where header manipulation leads to token leakage. While exact code isn't available, Craft CMS's MVC structure and the documented attack pattern strongly indicate this controller action as the vulnerable component.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| craftcms/cms | composer | < 3.7.36 | 3.7.36 |