High severity8.8NVD Advisory· Published Jan 3, 2022· Updated Jun 17, 2026
CVE-2021-25994
CVE-2021-25994
Description
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
userfrosting/userfrostingPackagist | >= 0.3.1, < 4.6.3 | 4.6.3 |
Affected products
30.3.1+ 1 more
- (no CPE)range: 0.3.1
- cpe:2.3:a:userfrosting:userfrosting:*:*:*:*:*:*:*:*range: >=0.3.1,<4.6.3
Patches
Vulnerability mechanics
References
4- github.com/userfrosting/UserFrosting/commit/796dd78757902435d1bd286415feea78098e45banvdPatchThird Party AdvisoryWEB
- www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25994nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-cv25-3gmg-c6m8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-25994ghsaADVISORY
News mentions
0No linked articles in our index yet.