SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-7903

Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.

LOW 3.7EPSS 1.13%

Does this matter?

Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.

Description

Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.

CVSS 3.0
3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.13% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
dotclear/dotclear
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.