CVE-2016-10073

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
23/05/2017
Last modified:
20/04/2025

Description

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:* 2.3.0 (including)