Descripción
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password reset URL sent to any user by injecting this header when triggering the forgot-password flow. When the victim clicks the poisoned link, their reset token is exfiltrated to the attacker-s server. The attacker then uses the token on the real instance to reset the victim-s password and destroy their 2FA configuration, achieving full account takeover. This issue has been patched in version 0.23.6.
CVSS 8.1EPSS 0.47600000000000003%Riesgo 0.84
Ver fuente- Publicación
- 2026-05-09 20:16:30
- Versiones afectadas
- <0.23.6
- Tipo
- Installed app
- Última modificación
- 2026-07-24 19:10:00
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N