Unrated severityNVD Advisory· Published Feb 12, 2025· Updated Feb 12, 2025
mailcow: dockerized vulnerable to password reset poisoning
CVE-2025-25198
Description
mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the Host HTTP header to generate a password reset link pointing to an attacker-controlled domain. This can lead to account takeover if a user clicks the poisoned link. Version 2025-01a contains a patch. As a workaround, deactivate the password reset functionality by clearing Notification email sender and Notification email subject under System -> Configuration -> Options -> Password Settings.
Affected products
1- Range: < 2025-01a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-3mvx-qw4r-fcqfmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.