ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:18:45.658Z

Reserved: 2020-10-23T00:00:00

Link: CVE-2020-27687

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-18T19:15:14.767

Modified: 2024-11-21T05:21:39.017

Link: CVE-2020-27687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.