PT-2026-36770 · Phpbb · Phpbb
Published
2026-05-04
·
Updated
2026-05-29
·
CVE-2026-29199
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
phpBB versions prior to 3.3.16
Description
Host Header Injection occurs when
force server vars is disabled, allowing the server's hostname to be extracted from the HTTP Host header to generate password reset link URLs. An attacker capable of manipulating the Host header, potentially through missing header validation by the webserver or misconfigured host setup, can cause password reset emails to include links pointing to a domain under their control, which may lead to account takeover.Recommendations
Update to version 3.3.16 or later.
Enable the
force server vars setting to prevent the use of the HTTP Host header for generating URLs.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpbb