Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting t…
Medium CVSS 6.8
Summary
Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full accou…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/GladysAssistant/Gladys/releases/tag/v5.1.0
- https://gladysassistant.com/blog/gladys-5-1-integration-widgets-and-scenes/
- https://www.vulncheck.com/advisories/gladys-assistant-password-reset-link-poisoning-via-forgot-password-endpoint
Timeline
- nvd_ingest NVD