CVE-2025-61543
Last modified
CVE-2025-61543 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can manipulate the Host header to send malicious reset links, enabling phishing attacks or account takeover.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-61543?
How severe is CVE-2025-61543?
How do I fix CVE-2025-61543?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-61532Cross Site Scripting vulnerability in SVX Portal v.2.7A to e…6.1
- CVE-2025-61536FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-r…8.2
- CVE-2025-61539Cross site scripting (XSS) vulnerability in Ultimate PHP Boa…6.1
- CVE-2025-6154A vulnerability was found in PHPGurukul Hostel Management Sy…9.8
- CVE-2025-61540SQL injection vulnerability in Ultimate PHP Board 2.2.7 via …6.5
- CVE-2025-61541Webmin 2.510 is vulnerable to a Host Header Injection in the…7.1
- CVE-2025-61546There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetU…9.1
- CVE-2025-61547Cross-Site Request Forgery (CSRF) is present on all function…6.8
- CVE-2025-61548SQL Injection is present on the hfInventoryDistFormID parame…9.8
- CVE-2025-61549Cross-Site Scripting (XSS) is present on the LoginID paramet…6.1
- CVE-2025-6155A vulnerability was found in PHPGurukul Hostel Management Sy…9.8
- CVE-2025-61550Cross-Site Scripting (XSS) is present on the ctl00_Content01…5.4
Are you affected by CVE-2025-61543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
