CVE-2016-7903 affects Dotclear before version 2.10.3, allowing remote attackers to manipulate password reset links. This low-severity vulnerability (CVSS 3.7) requires a specific web server configuration where the Host header isn't part of routing, making attacks more complex. While it could lead to unauthorized password resets, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.10.2CPE matchmatch criteria | cpe:2.3:a:dotclear:dotclear:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.