Beehive Forum Host Header Injection Vulnerability in Password Reset Functionality

Vulnerability

A host header injection vulnerability has been identified in Beehive Forum version 1.5.2, specifically within the password reset feature. This vulnerability allows attackers to manipulate password reset requests by injecting a malicious host header. As a result, they can intercept password reset tokens and change the passwords of victims' accounts without requiring direct authentication.

Impact

Exploitation of this vulnerability leads to unauthorized account access through password reset manipulation, allowing attackers to change passwords and take over accounts.

Reproduction

To reproduce this vulnerability, send a password reset request while injecting a malicious host header. This can be done using a tool like Burp Suite or by modifying the request headers in a script. Once the request is intercepted, extract the password reset token from the response. Then, use the token to change the password of the targeted account.

Added: Jan 14, 2026, 12:25 AM
Updated: Jan 14, 2026, 12:25 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.5
exploitability
7.5
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.