« Volver al listado

CVE-2026-43935

Estado: AplazadaAlta (8.1)—

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. This can lead to phishing attacks, account takeover, or other security risks. The severity is high, as the vulnerability affects a critical function related to user authentication. This vulnerability is fixed in 2.3.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Host Header Injection en página de reset de contraseña con UI:R (requiere interacción del usuario para hacer clic en enlace malicioso) = T1203. Impactos: phishing via correo falso (T1566.002) y takeover de cuentas (T1078.001).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-43935",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-43935",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-26T15:49:32.402267Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "e107inc",
          "product": "e107",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.3.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-26T16:16:25.390",
  "references": [
    {
      "url": "https://github.com/e107inc/e107/commit/04511f9f1d6e97c31ba7cc5bf7f1f9a19d221db6",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/e107inc/e107/commit/b0dee8234e273debbf7a8ae054de464f1008f357",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/e107inc/e107/commit/c4f9f71b0fd695545d0f09e2277b6f70ff4660fc",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/e107inc/e107/security/advisories/GHSA-7pmw-jwvr-cq2x",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/e107inc/e107/security/advisories/GHSA-7pmw-jwvr-cq2x",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-807"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. This can lead to phishing attacks, account takeover, or other security risks. The severity is high, as the vulnerability affects a critical function related to user authentication. This vulnerability is fixed in 2.3.4."
    },
    {
      "lang": "es",
      "value": "e107 es un sistema de gestión de contenido (CMS). Antes de 2.3.4, una vulnerabilidad de inyección de encabezado Host en la página de restablecimiento de contraseña permite a los atacantes manipular el encabezado Host para generar enlaces de restablecimiento de contraseña que apuntan a dominios controlados por el atacante. Esto puede llevar a ataques de phishing, toma de control de cuentas u otros riesgos de seguridad. La severidad es alta, ya que la vulnerabilidad afecta una función crítica relacionada con la autenticación de usuarios. Esta vulnerabilidad está corregida en 2.3.4."
    }
  ],
  "lastModified": "2026-07-24T11:10:00.170",
  "sourceIdentifier": "security-advisories@github.com"
}