{"id":"CVE-2022-29933","aliases":["GHSA-5cjr-78cq-3wrg"],"url":"https://o3.security/vulnerability/CVE-2022-29933","summary":"Improper account password reset in Craft CMS","details":"Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the vendor's position is that a customer can already work around this by adjusting the configuration (i.e., by not using the default configuration).","published":"2022-05-09T17:48:45Z","modified":"2026-08-12T03:51:48.232895363Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.04529,"percentile":0.90863,"asOf":"2026-08-30"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"3.7.36"}],"fix":null,"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/166989/Craft-CMS-3.7.36-Password-Reset-Poisoning-Attack.html"},{"type":"WEB","url":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md"},{"type":"WEB","url":"https://sec-consult.com/vulnerability-lab/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29933.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29933"},{"type":"ADVISORY","url":"https://sec-consult.com/vulnerability-lab/advisory/password-reset-poisoning-attack-craft-cms/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.232895363Z"}}