CNNVD-202510-2360 Information

CNNVD ID

CNNVD-202510-2360

CVE-2025-22381

  • CNNVD Published: 2025-10-16

Description (Chinese)

aggie是Technology & International Development Lab开源的一个用于使用社交媒体和其他资源跟踪选举或自然灾害等实时事件周围的事件的软件。 Aggie 2.6.1版本存在安全漏洞,该漏洞源于忘记密码功能中存在主机标头注入,可能导致攻击者重置用户密码。

Description (English)

Aggie is a software source for the use of social media and other resources to track events around real-time events such as elections or natural disasters. There is a security loophole in version 2.6.1 of Aggie, which stems from the omission of the host header injection in the password function, which could lead to the attacker changing the user password.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Technology & International Development Lab

Published

2025-10-16

Last Modified

2026-02-24

References

https://github.com/TID-Lab/aggie/tree/a9d5becaff3ea90720ea7213c80825e253b8a730 https://github.com/bugdotexe/Vulnerability-Research/tree/main/CVE-2025-22381

Share on: