PILOS account takeover through password reset poisoning
CVE-2023-47107
8.8HIGH
What is CVE-2023-47107?
The PILOS application, an open-source front-end for BigBlueButton servers featuring a load balancer, contains a vulnerability in its password reset functionality. This issue arises when the application utilizes the hostname from the request's host header to generate the password reset URL. An attacker could manipulate this URL to redirect users to their own server, potentially exposing sensitive information such as the password reset token if the compromised link is followed. This vulnerability primarily impacts local user accounts and demands that the password reset feature be activated. A fix has been implemented in version 2.3.0.
Affected Version(s)
PILOS >= 2.0.0, < 2.3.0
