userfrosting/UserFrosting

userfrosting/UserFrosting

Releases130
Frequency1 month 3 days
Last Release
Stars1.66K
Modern PHP user login and management framework

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.8 MEDIUM

In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.