CVE-2022-50910
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.
- CVSS 4.0
- 8.5 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-640
- Affected
- beehiveforum/beehive forum
- Source
- disclosure@vulncheck.com
References
- https://imgur.com/a/hVlgpCgExploit
- https://sourceforge.net/projects/beehiveforum/Product
- https://www.beehiveforum.co.uk/Product
- https://www.exploit-db.com/exploits/50923Exploit
- https://www.vulncheck.com/advisories/beehive-forum-account-takeoverThird Party Advisory
- https://www.exploit-db.com/exploits/50923Exploit
- https://www.vulncheck.com/advisories/beehive-forum-account-takeoverThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.