{"id":"GHSA-cv25-3gmg-c6m8","summary":"Injection in UserFrosting","details":"In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.","aliases":["CVE-2021-25994"],"modified":"2023-11-08T04:05:19.920920Z","published":"2022-01-06T22:22:32Z","database_specific":{"github_reviewed_at":"2022-01-06T19:40:35Z","nvd_published_at":"2022-01-03T07:15:00Z","cwe_ids":["CWE-74"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25994"},{"type":"WEB","url":"https://github.com/userfrosting/UserFrosting/commit/796dd78757902435d1bd286415feea78098e45ba"},{"type":"PACKAGE","url":"https://github.com/userfrosting/UserFrosting"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25994"}],"affected":[{"package":{"name":"userfrosting/userfrosting","ecosystem":"Packagist","purl":"pkg:composer/userfrosting/userfrosting"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.3.1"},{"fixed":"4.6.3"}]}],"versions":["4.1.0-Alpha","4.1.1-alpha","4.1.2-alpha","v4.1.10-alpha","v4.1.11-alpha","v4.1.12-alpha","v4.1.13-alpha","v4.1.14-alpha","v4.1.15-alpha","v4.1.16","v4.1.17","v4.1.18","v4.1.19","v4.1.20","v4.1.21","v4.1.22","v4.1.3-alpha","v4.1.4-alpha","v4.1.5-alpha","v4.1.6-alpha","v4.1.7-alpha","v4.1.8-alpha","v4.1.9-alpha","v4.2.0","v4.2.0-alpha.1","v4.2.0-alpha.2","v4.2.0-beta.1","v4.2.0-beta.2","v4.2.2","v4.2.3","v4.2.4","v4.3.0","v4.3.0-beta.1","v4.3.1","v4.3.2","v4.3.3","v4.3.4","v4.4.0","v4.4.1","v4.4.2","v4.4.3","v4.4.4","v4.4.5","v4.5.0","v4.5.1","v4.5.2","v4.6.0","v4.6.1","v4.6.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-cv25-3gmg-c6m8/GHSA-cv25-3gmg-c6m8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}