CVE-2017-8385: Medium severity craft cms vulnerability
Published May 1, 2017
·Updated
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<2.6.2976
2.6.2976
Craft CMS<=2.6.2974
Event History
May 1, 2017
CVE Published
via MITRE·06:08 AM
Data Sourced
via MITRE·06:08 AM
Description
May 17, 2022
Advisory Published
via GitHub·02:46 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-8385?
CVE-2017-8385 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-8385?
To fix CVE-2017-8385, upgrade Craft CMS to version 2.6.2976 or later.
3
What types of attacks can CVE-2017-8385 allow?
CVE-2017-8385 can allow attackers to craft malicious URLs in forgot-password email messages.
4
Who is affected by CVE-2017-8385?
Users of Craft CMS versions prior to 2.6.2976 are affected by CVE-2017-8385.
5
What does CVE-2017-8385 exploit?
CVE-2017-8385 exploits the lack of validation on URL modification in email messages.