PT-2025-33735 · Unknown · Nginx Proxy Manager

Jfoz1010

+1

·

Published

2025-08-19

·

Updated

2025-08-19

·

CVE-2025-50579

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Nginx Proxy Manager version 2.12.3

Description:

A Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized domains to access sensitive data, specifically JSON Web Tokens (JWT), due to improper validation of the Origin header. This enables attackers to intercept tokens using a browser script and exfiltrate them to a remote attacker-controlled server, potentially leading to unauthorized actions.

Recommendations:

Update Nginx Proxy Manager to a version that addresses this misconfiguration.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-50579

Affected Products

Nginx Proxy Manager