PT-2025-43525 · Unknown+1 · Axewater Sharewarez+1
Published
2025-10-23
·
Updated
2025-10-28
·
CVE-2025-61136
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
axewater sharewarez version 2.4.3
Description
A Host Header Injection flaw exists in the password reset functionality of the software. This allows remote attackers to potentially take over accounts by manipulating the Host header during password reset link generation, specifically when Flask's
url for( external=True) is used without a defined SERVER NAME. The vulnerability enables password reset poisoning. The affected component is the password reset component.Recommendations
Ensure a fixed
SERVER NAME is configured when using Flask's url for( external=True) function to generate password reset links.Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flask
Axewater Sharewarez