Description
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.
Problem types
Weak Password Recovery Mechanism for Forgotten Password
Product status
Credits
Pablo Santiago
References
www.exploit-db.com/exploits/50923
www.vulncheck.com/advisories/beehive-forum-account-takeover
www.exploit-db.com/exploits/50923 (ExploitDB-50923)
www.beehiveforum.co.uk/ (Beehive Forum Official Website)
sourceforge.net/projects/beehiveforum/ (Beehive Forum SourceForge Project)
imgur.com/a/hVlgpCg (Proof of Concept Imgur)
www.vulncheck.com/advisories/beehive-forum-account-takeover (VulnCheck Advisory: Beehive Forum - Account Takeover)