CVE-2026-100870
HIGH
8,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.
640
Weak Password Recovery Mechanism for Forgotten Password
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Availability
Integrity
Other
Potential Impacts:
Gain Privileges Or Assume Identity
Dos: Resource Consumption (Other)
Other
Applicable Platforms
All platforms may be affected
https://github.com/Sylius/Sylius
https://github.com/Sylius/Sylius/commit/1255d75b20d3d88a5e5c8d46791504134c838480
https://github.com/Sylius/Sylius/pull/19215
https://github.com/Sylius/Sylius/releases/tag/v2.2.9
https://github.com/Sylius/Sylius/security/advisories/GHSA-77w3-2367-7xvq
https://www.vulncheck.com/advisories/sylius-before-1.12.25-1.13.17-1.14.20-2.1.…