CVE-2025-53373

CVSS

No CVSS.

N

atours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server domain in the Host header when requesting the /forgetpassword endpoint. This vulnerability is fixed with commit 7401793a8d9ed0f0c250c4e0ee2815d685d7a70b.

Configurations

No configuration.

History

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Natours es una API de reserva de tours. El atacante puede tomar el control fácilmente de cualquier cuenta víctima inyectando un dominio de servidor controlado por el atacante en el encabezado del host al solicitar el endpoint /forgetpassword. Esta vulnerabilidad se corrige con el commit 7401793a8d9ed0f0c250c4e0ee2815d685d7a70b.

07 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 16:15

Updated : 2025-07-08 16:18


NVD link : CVE-2025-53373

Mitre link : CVE-2025-53373

CVE.ORG link : CVE-2025-53373


JSON object : View

Products Affected

No product.

CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password