Weak Password Recovery Mechanism for Forgotten Password in Sylius - #VU146815
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to take over an administrator account.
The vulnerability exists due to weak password recovery mechanism in the administrator password-reset email link generation when building the reset URL from the request Host header. A remote attacker can trigger a password-reset email and supply a crafted Host header so the reset link points to an attacker-controlled domain to take over an administrator account.
User interaction is required because the administrator must click the crafted reset link in the genuine password-reset email.