A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.
References
Configurations
No configuration.
History
23 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
| CWE | CWE-620 |
23 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-23 15:15
Updated : 2025-10-23 17:15
NVD link : CVE-2025-61132
Mitre link : CVE-2025-61132
CVE.ORG link : CVE-2025-61132
JSON object : View
Products Affected
No product.
CWE
CWE-620
Unverified Password Change
