CVE-2022-50910
Severity CVSS v4.0:
HIGH
Type:
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Publication date:
13/01/2026
Last modified:
13/01/2026
Description
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



