CVE-2023-53958

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-19 21:15

Updated : 2025-12-23 14:51


NVD link : CVE-2023-53958

Mitre link : CVE-2023-53958

CVE.ORG link : CVE-2023-53958


JSON object : View

Products Affected

No product.

CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password