Executive brief
CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.
Affected products
- PyPI indico
Junglewise Threat Intelligence
CVE-2021-30185 · Severity: low · CVSS 3.1 · Published 2021-04-07
Technologies: indico (PyPI). Vendors: PyPI.
CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.