Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100870— Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning via Host Header

Quick assessment

Affected
Sylius Sylius
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Sylius 在 1.12.25、1.13.17、1.14.20、2.1.16 以及 2.2.9 之前的版本中,构建管理员密码重置链接时使用了请求中的 Host 头,且未对其进行任何验证。这使得未经身份验证的攻击者能够将密码重置令牌重定向至其控制的域名。攻击者可以通过伪造 Host 头,对已知管理员邮箱地址发起密码重置请求,从而截获有效的密码重置令牌,并接管管理员账户。

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100870

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning via Host Header
Source: CVE Program / CVE List V5
Vulnerability Description
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
忘记口令恢复机制弱
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Sylius Sylius 1.12.0 ~ 1.12.25 -

II. Public POCs for CVE-2026-100870

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100870

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100870 (1)

Vendor Pages for CVE-2026-100870 (1)

Other References for CVE-2026-100870 (4)

Same Patch Batch · Sylius · 2026-09-27 · 4 CVEs total

CVE-2026-100871 8.8 HIGH Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows A
CVE-2026-100872 7.5 HIGH Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite
CVE-2026-100869 5.9 MEDIUM Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API

IV. Related Vulnerabilities

V. Comments for CVE-2026-100870

No comments yet


Leave a comment