PILOS account takeover through password reset poisoning
CVE-2023-47107

8.8HIGH

Key Information:

Vendor

Thm-health

Status
Vendor
CVE Published:
8 November 2023

What is CVE-2023-47107?

The PILOS application, an open-source front-end for BigBlueButton servers featuring a load balancer, contains a vulnerability in its password reset functionality. This issue arises when the application utilizes the hostname from the request's host header to generate the password reset URL. An attacker could manipulate this URL to redirect users to their own server, potentially exposing sensitive information such as the password reset token if the compromised link is followed. This vulnerability primarily impacts local user accounts and demands that the password reset feature be activated. A fix has been implemented in version 2.3.0.

Affected Version(s)

PILOS >= 2.0.0, < 2.3.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.