PT-2026-99540 · Sylius · Sylius
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sylius versions prior to 1.12.25
Sylius versions prior to 1.13.17
Sylius versions prior to 1.14.20
Sylius versions prior to 2.1.16
Sylius versions prior to 2.2.9
Description
Administrator password-reset links are constructed using the request Host header without proper validation. This allows unauthenticated attackers to use forged Host headers when requesting password resets for known administrator email addresses, redirecting the resulting reset tokens to attacker-controlled domains to facilitate account takeover.
Recommendations
Update to version 1.12.25 or later.
Update to version 1.13.17 or later.
Update to version 1.14.20 or later.
Update to version 2.1.16 or later.
Update to version 2.2.9 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sylius