{"id":"CVE-2021-25994","aliases":["GHSA-cv25-3gmg-c6m8"],"url":"https://o3.security/vulnerability/CVE-2021-25994","summary":"Injection in UserFrosting","details":"In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.","published":"2022-01-03T07:15:07.243Z","modified":"2026-07-09T05:13:47.183621Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.01549,"percentile":0.72736,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"userfrosting/userfrosting","fixedVersion":"4.6.3"}],"fix":{"url":"https://github.com/userfrosting/UserFrosting/commit/796dd78757902435d1bd286415feea78098e45ba","label":"userfrosting/UserFrosting@796dd78"},"references":[{"type":"FIX","url":"https://github.com/userfrosting/UserFrosting/commit/796dd78757902435d1bd286415feea78098e45ba"},{"type":"EVIDENCE","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25994"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T05:13:47.183621Z"}}