CVE-2016-7903

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-7903
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7903.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-7903
Related
Published
2017-01-04T21:59:00Z
Modified
2025-04-12T13:49:28.937779Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.

References

Affected packages

Git / github.com/dotclear/dotclear

Affected ranges

Type
GIT
Repo
https://github.com/dotclear/dotclear
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

2.*

2.10.0
2.10.1
2.10.2
2.3.0
2.3.1
2.4.0
2.4.1.2
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.6-RC
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1