Vulnerability Description
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Beehiveforum | Beehive Forum | 1.5.2 |
Related Weaknesses (CWE)
References
- https://imgur.com/a/hVlgpCgExploit
- https://sourceforge.net/projects/beehiveforum/Product
- https://www.beehiveforum.co.uk/Product
- https://www.exploit-db.com/exploits/50923Exploit
- https://www.vulncheck.com/advisories/beehive-forum-account-takeoverThird Party Advisory
- https://www.exploit-db.com/exploits/50923Exploit
- https://www.vulncheck.com/advisories/beehive-forum-account-takeoverThird Party Advisory
FAQ
What is CVE-2022-50910?
CVE-2022-50910 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious ho...
How severe is CVE-2022-50910?
CVE-2022-50910 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-50910?
Check the references section above for vendor advisories and patch information. Affected products include: Beehiveforum Beehive Forum.