Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link can disclose the reset token, allowing the attacker to reset the victim's password and take over the account. Exploitation also requires a configured email gateway and an email address for the victim, while some reverse proxy configurations may reject the hostile Host header. This issue is fixed in version 2026.58. | |
| Title | SysReptor: Host header injection might allow account takeover | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T19:49:53.040Z
Reserved: 2026-08-26T16:26:08.967Z
Link: CVE-2026-81179
Updated: 2026-09-18T19:49:49.088Z
Status : Deferred
Published: 2026-09-18T18:17:15.617
Modified: 2026-09-18T20:17:23.470
Link: CVE-2026-81179
No data.
OpenCVE Enrichment
Updated: 2026-09-19T12:00:08Z