CVE-2021-25994 is a Host Header Injection vulnerability affecting Userfrosting versions v0.3.1 to v4.6.2. This high-severity vulnerability (CVSS 8.8) allows an unauthenticated attacker to reset a victim's password and take over their account by luring them to click a malicious link. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for complete compromise of confidentiality, integrity, and availability is significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.3.1, < 4.6.3CPE matchmatch criteria | cpe:2.3:a:userfrosting:userfrosting:*:*:*:*:*:*:*:* | ||
<= 4.6.2CPE match | cpe:2.3:a:userfrosting:userfrosting:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.