VYPR
High severity8.8NVD Advisory· Published May 2, 2022· Updated Jun 17, 2026

CVE-2022-23064

CVE-2022-23064

Description

In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
snipe/snipe-itPackagist
>= 3.0-alpha, < 5.4.05.4.0

Affected products

8
  • Snipeitapp/Snipe Itcpe-rescue7 versions
    v3.0-alpha+ 6 more
    • (no CPE)range: v3.0-alpha
    • cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*range: >=3.0.0,<=5.3.7
    • cpe:2.3:a:snipeitapp:snipe-it:3.0.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:snipeitapp:snipe-it:3.0.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:snipeitapp:snipe-it:3.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:snipeitapp:snipe-it:3.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:snipeitapp:snipe-it:3.0.0:beta3:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 3.0-alpha, < 5.4.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.