9.3
CVE-2025-70948
- EPSS 0.35%
- Veröffentlicht 05.03.2026 00:00:00
- Zuletzt bearbeitet 27.04.2026 19:08:32
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.268 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.3 | 2.8 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
|
CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
https://github.com/perfood/couch-auth
https://www.npmjs.com/package/@perfood/couch-auth
https://gist.github.com/0xHunterr/38aab644874ca9f4646524c5b01cfe5e