CVE-2025-61543 describes a Host Header Injection vulnerability in CraftMyCMS version 4.0.2.2's password reset functionality, where the system directly uses the HTTP_HOST header to generate password reset links. This allows an attacker to craft malicious links for phishing or account takeover. Rated as HIGH severity with a CVSS score of 7.1, the vulnerability is network-exploitable with low attack complexity, requiring user interaction and potentially leading to partial confidentiality loss and high availability impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.