PT-2025-42474 · Unknown · Felixriddle Dev-Jobs-Handlebars
Published
2025-10-16
·
Updated
2025-10-16
·
CVE-2025-61536
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
FelixRiddle dev-jobs-handlebars version 1.0
Description
The software uses absolute password-reset links that rely on the untrusted
req.headers.host header and enforces the http:// scheme. This allows an attacker who can control the Host header, or exploit a misconfigured proxy or load balancer, to manipulate the reset links to point to attacker-controlled domains or be delivered via insecure HTTP. This can lead to token theft, phishing, and account takeover. The vulnerable parameter is req.headers.host.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Felixriddle Dev-Jobs-Handlebars