PT-2025-33735 · Unknown · Nginx Proxy Manager
Jfoz1010
+1
·
Published
2025-08-19
·
Updated
2025-09-24
·
CVE-2025-50579
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Nginx Proxy Manager version 2.12.3
Description:
A Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized domains to access sensitive data, specifically JSON Web Tokens (JWT), due to improper validation of the Origin header. This enables attackers to intercept tokens using a browser script and exfiltrate them to a remote attacker-controlled server, potentially leading to unauthorized actions.
Recommendations:
Update Nginx Proxy Manager to a version that addresses this misconfiguration.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nginx Proxy Manager