PT-2026-25381 · Kasuganosoras+1 · Pigeon
Mabjr33
+1
·
Publicado
2026-03-13
·
Atualizado
2026-03-16
·
CVE-2026-32616
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pigeon versions prior to 1.0.201
Description
Pigeon is a message board/notepad/social system/blog. The application uses
$ SERVER['HTTP HOST'] without validation when constructing email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in an HTTP request, causing the verification link sent to a user’s email to point to an attacker-controlled domain. This can lead to account takeover by stealing the email verification token. The vulnerable component uses the $ SERVER['HTTP HOST'] variable to construct the email verification URL.Recommendations
Update Pigeon to version 1.0.201 or later.
Exploit
Correção
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pigeon