{"id":"CVE-2023-53958","summary":"LDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host Header","details":"LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.","modified":"2026-08-15T04:07:07.159832216Z","published":"2025-12-19T21:05:52.944Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-640"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53958.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53958.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53958"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ldap-tool-box-self-service-password-account-takeover-via-http-host-header"},{"type":"PACKAGE","url":"https://github.com/ltb-project/self-service-password"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/51275"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ltb-project/self-service-password","events":[{"introduced":"859eae793bbaa7e07e5f1da518f5f2de9f5d1b27"},{"last_affected":"859eae793bbaa7e07e5f1da518f5f2de9f5d1b27"}],"database_specific":{"extracted_events":[{"introduced":"1.5.2"},{"last_affected":"1.5.2"}],"source":"AFFECTED_FIELD"}}],"versions":["1.5.2","v1.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53958.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}