Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2016-7903

LOW · 3.7 CVSS Gepubliceerd: CWE-264

Beschrijving

Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.

Vendors

Dotclear

Affected products

Dotclear

References