CVE-2023-48205: Medium severity jorani vulnerability
Published Dec 7, 2023
·Updated
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
Affected Software
1 affected component
Jorani Leave Management System=1.0.2
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-48205?
CVE-2023-48205 is considered a medium severity vulnerability due to the potential for remote attackers to exploit header spoofing.
2
How do I fix CVE-2023-48205?
To fix CVE-2023-48205, ensure that Host header validation is implemented to mitigate spoofing risks.
3
What systems are affected by CVE-2023-48205?
CVE-2023-48205 affects Jorani Leave Management System version 1.0.2.
4
What impact does CVE-2023-48205 have on password reset functionality?
CVE-2023-48205 allows an attacker to manipulate the Host header, potentially leading to phishing in password reset emails.
5
Is there a patch available for CVE-2023-48205?
As of now, there is no official patch released for CVE-2023-48205; users should implement workarounds until a fix is provided.