VulnerabilityModified
CVE-2016-7903
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
LOW 3.7EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- dotclear/dotclear
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2016/10/05/5Mailing List
- http://www.securityfocus.com/bid/93439
- https://dotclear.org/blog/post/2016/11/01/Dotclear-2.10.3Patch, Vendor Advisory
- https://hg.dotclear.org/dotclear/rev/bb06343f4247Patch
- http://www.openwall.com/lists/oss-security/2016/10/05/5Mailing List
- http://www.securityfocus.com/bid/93439
- https://dotclear.org/blog/post/2016/11/01/Dotclear-2.10.3Patch, Vendor Advisory
- https://hg.dotclear.org/dotclear/rev/bb06343f4247Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.