Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.13%
Published
Jan 4, 2017
Modified
May 6, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
Weaknesses (CWE)
Affected Products (1)
References (8)