PT-2025-43525 · Unknown+1 · Axewater Sharewarez+1

Published

2025-10-23

·

Updated

2025-10-28

·

CVE-2025-61136

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions axewater sharewarez version 2.4.3
Description A Host Header Injection flaw exists in the password reset functionality of the software. This allows remote attackers to potentially take over accounts by manipulating the Host header during password reset link generation, specifically when Flask's url for( external=True) is used without a defined SERVER NAME. The vulnerability enables password reset poisoning. The affected component is the password reset component.
Recommendations Ensure a fixed SERVER NAME is configured when using Flask's url for( external=True) function to generate password reset links.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61136

Affected Products

Flask
Axewater Sharewarez