CVSS v3
8.8
HIGH
Score EPSS
2.3 %
probabilité d’exploitation
CISA KEV
Non
exploitation connue
Exploitation
—
statut SSVC
Description
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the vendor's position is that a customer can already work around this by adjusting the configuration (i.e., by not using the default configuration).
Détails techniques
- Publiée le
- 2022-05-09
Questions fréquentes
Qu’est-ce que CVE-2022-29933 ?
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the vendor's position is that a customer can already work around this by adjusting the configuration (i.e., by not using the default configuration).
CVE-2022-29933 est-elle activement exploitée ?
Aucune exploitation active de CVE-2022-29933 n’est confirmée. Le score EPSS est de 2.3 %, soit la probabilité estimée d’exploitation dans les 30 prochains jours.
Quel est le score CVSS de CVE-2022-29933 ?
CVE-2022-29933 a un score de base CVSS v3 de 8.8 (gravité HIGH).
CVE-2022-29933 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite
Autres vulnérabilités 2022 à trier
Classées par probabilité d’exploitation (EPSS).