Critical severity9.8NVD Advisory· Published Jan 13, 2026· Updated Jun 17, 2026
CVE-2022-50910
CVE-2022-50910
Description
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:beehiveforum:beehive_forum:1.5.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:beehiveforum:beehive_forum:1.5.2:*:*:*:*:*:*:*
- (no CPE)range: <1.5.2
- (no CPE)range: 1.5.2
Patches
Vulnerability mechanics
References
5- imgur.com/a/hVlgpCgnvdExploit
- www.exploit-db.com/exploits/50923nvdExploit
- www.vulncheck.com/advisories/beehive-forum-account-takeovernvdThird Party Advisory
- sourceforge.net/projects/beehiveforum/nvdProduct
- www.beehiveforum.co.uknvdProduct
News mentions
0No linked articles in our index yet.