Host Header Injection Vulnerability in ThingsBoard by ThingsBoard
CVE-2020-27687
8.8HIGH
What is CVE-2020-27687?
ThingsBoard versions prior to v3.2 are susceptible to a Host header injection vulnerability within password-reset emails. This security flaw enables attackers to craft malicious links that can redirect victims to an attacker-controlled server. The absence of proper validation for the Host header facilitates the execution of this exploit, potentially compromising user accounts and sensitive information.
