Executive brief
Password Manager, an application used to store and manage credentials, contains a vulnerability in how it processes web requests. An attacker can send specially crafted messages to manipulate the application's internal links and responses. This could lead to users being directed to incorrect services or the exposure of limited sensitive information.
Technical details
A Host Header Injection vulnerability (CWE-644) exists in Password Manager due to improper neutralization of HTTP headers. A remote, unauthenticated attacker can manipulate the Host header via specially crafted requests. If the application uses this header to generate absolute URLs in links or password reset emails, it can lead to web cache poisoning or redirection of sensitive data to an attacker-controlled domain. The vulnerability requires some user interaction and was addressed in the update released on August 7, 2025.
Affected products
- Password Manager (eusonlito) Password Manager versions prior to August 7, 2025
Timeline
- 2025-08-07: patched: Vulnerabilities fixed by the Password Manager team.
- 2026-05-06: disclosed: Initial disclosure by INCIBE-CERT.
- 2026-06-17: advisory: NVD publication date.