{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-01T02:33:46.311","vulnerabilities":[{"cve":{"id":"CVE-2021-25980","sourceIdentifier":"vulnerabilitylab@mend.io","published":"2021-11-11T07:15:11.380","lastModified":"2026-06-17T03:42:43.340","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account."},{"lang":"es","value":"En Talkyard, las versiones v0.04.01 hasta v0.6.74-WIP-63220cb, versiones v0.2020.22-WIP-b2e97fe0e hasta v0.2021.02-WIP-879ef3fe1 y versiones tyse-v0.2021.02-879ef3fe1-regular hasta tyse-v0.2021.28-af66b6905-regular, son vulnerables a una inyección de encabezados de host. Atrayendo a un usuario de la aplicación víctima para que haga clic en un enlace, un atacante no autenticado puede usar la funcionalidad \"forgot password\" para restablecer la contraseña de la víctima y hacerse con su cuenta"}],"affected":[{"source":"vulnerabilitylab@mend.io","affectedData":[{"vendor":"debiki","product":"talkyard","versions":[{"version":"v0.04.01","lessThan":"v0*","versionType":"custom","status":"affected"},{"version":"v0.2020.22-WIP-b2e97fe0e","lessThan":"v0.2020*","versionType":"custom","status":"affected"},{"version":"v0.2021","lessThanOrEqual":"v0.2021.02-WIP-879ef3fe1","versionType":"custom","status":"affected"},{"version":"tyse-v0.2021.02-879ef3fe1-regular","lessThan":"tyse-v0.2021*","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"vulnerabilitylab@mend.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-30T15:29:27.390742Z","id":"CVE-2021-25980","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vulnerabilitylab@mend.io","type":"Secondary","description":[{"lang":"en","value":"CWE-74"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:talkyard:talkyard:*:*:*:*:*:*:*:*","versionStartIncluding":"0.04.01","versionEndIncluding":"0.6.74-wip-63220cb","matchCriteriaId":"C3AD90CD-FF57-4CA1-85B3-3EADB9159EB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:talkyard:talkyard:*:*:*:*:*:*:*:*","versionStartIncluding":"0.2020.22-wip-b2e97fe0e","versionEndIncluding":"0.2021.02-wip-879ef3fe1","matchCriteriaId":"74C594EE-CC21-4F19-9E76-AB4A2A5B8ACA"},{"vulnerable":true,"criteria":"cpe:2.3:a:talkyard:talkyard:*:*:*:*:*:*:*:*","versionStartIncluding":"tyse-v0.2021.02-879ef3fe1-regular","versionEndIncluding":"tyse-v0.2021.28-af66b6905-regular","matchCriteriaId":"AE16449B-47FA-4F64-868C-056B170CAB0D"}]}]}],"references":[{"url":"https://github.com/debiki/talkyard/commit/4067e191a909ed06f250d09a40e43aa5edbb0289","source":"vulnerabilitylab@mend.io","tags":["Patch","Third Party Advisory"]},{"url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25980","source":"vulnerabilitylab@mend.io","tags":["Third Party Advisory"]},{"url":"https://github.com/debiki/talkyard/commit/4067e191a909ed06f250d09a40e43aa5edbb0289","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25980","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}