CVE-2025-61543
HIGHCraftMyCMS 4.0.2.2 - Host Header Injection
Title source: llmDescription
A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can manipulate the Host header to send malicious reset links, enabling phishing attacks or account takeover.
Scores
CVSS v3
7.1
EPSS
0.0004
EPSS Percentile
11.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Details
CWE
CWE-284
Status
published
Published
Oct 16, 2025
Tracked Since
Feb 18, 2026