Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 27 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts. | |
| Title | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning via Host Header | |
| First Time appeared |
Sylius
Sylius sylius |
|
| Weaknesses | CWE-640 | |
| CPEs | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sylius
Sylius sylius |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T13:09:54.715Z
Reserved: 2026-09-27T00:20:54.408Z
Link: CVE-2026-100870
No data.
Status : Received
Published: 2026-09-27T13:16:38.240
Modified: 2026-09-27T13:16:38.240
Link: CVE-2026-100870
No data.
OpenCVE Enrichment
No data.
Weaknesses