PT-2025-52528 · Unknown · Ldap Tool Box Self Service Password

Tahar Bennacef

·

Published

2025-12-19

·

Updated

2025-12-20

·

CVE-2023-53958

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions LDAP Tool Box Self Service Password version 1.5.2
Description The software contains a password reset issue where attackers can manipulate HTTP Host headers during token generation. This allows crafting malicious password reset requests that generate tokens sent to a server controlled by the attacker. Successful exploitation could lead to account takeover by intercepting and using stolen reset tokens. The vulnerability involves manipulating the Host header during the token generation process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2023-53958

Affected Products

Ldap Tool Box Self Service Password