CVE-2025-22381 Details
Description
Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.
A host header injection vulnerability has been identified in Aggie version 2.6.1, specifically within the password reset feature. This vulnerability arises because the application generates absolute password reset URLs by using the untrusted 'Host' header without proper validation. As a result, attackers can inject malicious domains into the reset emails, potentially leading to phishing attacks, theft of password reset tokens, and unauthorized access to user accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 16, 2025CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bugdotexe/Vulnerability-Research/tree/main/CVE-2025-22381 | [email protected] | ExploitTechnical Description |
| https://github.com/pescada-dev/CVE-2025-22381 | [email protected] | |
| https://github.com/TID-Lab/aggie/tree/a9d5becaff3ea90720ea7213c80825e253b8a730 | [email protected] | ProductSource CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-620 | Unverified Password Change | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| TID-Lab Aggie | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 2, 2026 | CVE Modified | [email protected] |
| Oct 16, 2025 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | New CVE Received | [email protected] |
Volerion