Lucene search

K
prionPRIOn knowledge basePRION:CVE-2016-10073
HistoryMay 23, 2017 - 4:29 a.m.

Design/Logic Flaw

2017-05-2304:29:00
PRIOn knowledge base
www.prio-n.com
3

6.7 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.7%

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

CPENameOperatorVersion
vanillale2.3.0

6.7 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.7%