Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-23064


In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.


Published

2022-05-02T13:15:08.170

Last Modified

2024-11-21T06:47:54.833

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-74

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application snipeitapp snipe-it ≤ 5.3.7 Yes
Application snipeitapp snipe-it 3.0.0 Yes
Application snipeitapp snipe-it 3.0.0 Yes
Application snipeitapp snipe-it 3.0.0 Yes
Application snipeitapp snipe-it 3.0.0 Yes
Application snipeitapp snipe-it 3.0.0 Yes

References