Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability - CVE-2022-29933 - Vulnerability Database

Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability - CVE-2022-29933

High
Reference: CVE-2022-29933
Title: Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability
Overview:

Craft CMS through 3.7.36 allows a remote unauthenticated attacker who knows at least one valid username to reset the account39s password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically the attacker must send X-Forwarded-Host to the /index.phppadmin/actions/users/send-password-reset-email URI. NOTE: the vendor39s position is that a customer can already work around this by adjusting the configuration (i.e. by not using the default configuration).