Impact
A vulnerability in mailcow's password reset functionality allows an attacker to manipulate the Host HTTP
header to generate a password reset link pointing to an attacker-controlled domain. This can lead to account takeover if a user clicks the poisoned link.
Patches
2025-01a
Workarounds
Deactivate the password reset functionality by clearing Notification email sender
and Notification email subject
under System -> Configuration -> Options -> Password Settings
Credits
Donncha Ó Cearbhaill of Amnesty International's Security Lab
Impact
A vulnerability in mailcow's password reset functionality allows an attacker to manipulate the
Host HTTP
header to generate a password reset link pointing to an attacker-controlled domain. This can lead to account takeover if a user clicks the poisoned link.Patches
2025-01a
Workarounds
Deactivate the password reset functionality by clearing
Notification email sender
andNotification email subject
under System -> Configuration -> Options -> Password SettingsCredits
Donncha Ó Cearbhaill of Amnesty International's Security Lab