Description
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.
Problem types
Weak Password Recovery Mechanism for Forgotten Password
Product status
Credits
Tahar BENNACEF (aka tar.gz)
References
www.exploit-db.com/exploits/51275 (ExploitDB-51275)
github.com/ltb-project/self-service-password (Official Product Homepage)
www.vulncheck.com/...d-account-takeover-via-http-host-header (VulnCheck Advisory: LDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host Header)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.