CVE-2026-43935 Details
Description
e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. This can lead to phishing attacks, account takeover, or other security risks. The severity is high, as the vulnerability affects a critical function related to user authentication. This vulnerability is fixed in 2.3.4.
A Host Header Injection vulnerability has been identified in e107 versions prior to 2.3.4. This vulnerability allows attackers to manipulate the Host header on the password reset page, creating links that direct to attacker-controlled domains. Such an exploit could facilitate phishing attacks, account takeovers, or other security issues, as it undermines a critical user authentication function.
Users can upgrade to e107 version 2.3.4 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 26, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/e107inc/e107/security/advisories/GHSA-7pmw-jwvr-cq2x | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/e107inc/e107/commit/04511f9f1d6e97c31ba7cc5bf7f1f9a19d221db6 | [email protected] | Source CodeVendor |
| https://github.com/e107inc/e107/commit/b0dee8234e273debbf7a8ae054de464f1008f357 | [email protected] | Source CodeVendor |
| https://github.com/e107inc/e107/commit/c4f9f71b0fd695545d0f09e2277b6f70ff4660fc | [email protected] | Source CodeVendor |
| https://github.com/e107inc/e107/security/advisories/GHSA-7pmw-jwvr-cq2x | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-807 | Reliance on Untrusted Inputs in a Security Decision | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| e107 | <= 2.3.3 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |
Volerion